216.73.217.172

CVE-2024-13140

· Published 05/01/2025 12:15 · Modified 10/01/2025 21:34

Labels: CVE-2024-13140 2025-01-05CVE-2024-13140CWE-79[email protected]

Essential information

Published
05/01/2025 12:15
Modified
10/01/2025 21:34
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.3. Affected is an unknown function of the file /admin/article.php?action=upload_cover of the component Cover Upload Handler. The manipulation of the argument image leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
emlog / emlog cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:*

References