CVE-2019-16868: Path Traversal
Published Sep 25, 2019
·Updated
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dellallbak request with directory traversal sequences in the bak[] parameter.
Affected Software
2 affected components
Emlog emlog<=5.3.1
Emlog emlog=6.0.0-beta
Event History
Sep 25, 2019
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16868?
CVE-2019-16868 is an arbitrary file deletion vulnerability found in emlog through version 6.0.0-beta.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by making a request to admin/data.php?action=dell_all_bak with directory traversal sequences in the bak[] parameter.
3
What software versions are affected by CVE-2019-16868?
Emlog versions up to and including 5.3.1 and version 6.0.0-beta are affected by CVE-2019-16868.
4
What is the severity of CVE-2019-16868?
CVE-2019-16868 has a severity rating of critical with a CVSS score of 9.8.
5
Is there a fix available for CVE-2019-16868?
Yes, upgrading to a version of Emlog that is not affected by this vulnerability is recommended to fix CVE-2019-16868.