Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-79683
HistoryOct 07, 2023 - 12:00 a.m.

emlog deserialization vulnerability

2023-10-0700:00:00
China National Vulnerability Database
www.cnvd.org.cn
2
emlog
php
mysql
cms
deserialization vulnerability
remote attacker
arbitrary code
cache.php

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.5%

emlog is a PHP and MySQL based CMS builder for emlog personal developers. emlog pro v2.1.15 and previous versions of the existence of a deserialization vulnerability, the vulnerability stems from the application in the receipt of user-submitted serialized data insecure deserialization process, a remote attacker can exploit the vulnerability through the cache.php component to execute arbitrary code.

CPENameOperatorVersion
emlog emlog prole2.1.15

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.5%

Related for CNVD-2023-79683