CVE-2019-17073: Path Traversal
Published Oct 1, 2019
·Updated
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
Affected Software
2 affected components
Emlog emlog<=5.3.1
Emlog emlog=6.0.0-beta
Event History
Oct 1, 2019
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-17073.
2
What is the severity of CVE-2019-17073?
The severity of CVE-2019-17073 is medium with a severity value of 6.5.
3
How does this vulnerability affect the emlog software?
This vulnerability affects emlog software versions up to and including 5.3.1 and version 6.0.0-beta.
4
How can remote authenticated users exploit this vulnerability?
Remote authenticated users can exploit this vulnerability by sending a specially crafted request to admin/template.php?action=del&tpl=../ to perform directory traversal and delete arbitrary files.
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. Please refer to the official emlog documentation or vendor for the patch or update.