First published: Wed Sep 25 2019(Updated: )
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Emlog Emlog | <=5.3.1 | |
Emlog Emlog | =6.0.0-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16868 is an arbitrary file deletion vulnerability found in emlog through version 6.0.0-beta.
This vulnerability can be exploited by making a request to admin/data.php?action=dell_all_bak with directory traversal sequences in the bak[] parameter.
Emlog versions up to and including 5.3.1 and version 6.0.0-beta are affected by CVE-2019-16868.
CVE-2019-16868 has a severity rating of critical with a CVSS score of 9.8.
Yes, upgrading to a version of Emlog that is not affected by this vulnerability is recommended to fix CVE-2019-16868.