CVE-2020-21321: CSRF
Published Sep 15, 2021
·Updated
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
Affected Software
1 affected component
Emlog emlog=6.0.0
Event History
Sep 15, 2021
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Frequently Asked Questions
1
What is CVE-2020-21321?
CVE-2020-21321 is a vulnerability found in emlog v6.0 that allows attackers to perform Cross-Site Request Forgery (CSRF) attacks.
2
How does CVE-2020-21321 affect emlog v6.0?
CVE-2020-21321 allows attackers to arbitrarily add articles to the emlog v6.0 website.
3
What is the severity of CVE-2020-21321?
The severity of CVE-2020-21321 is medium with a severity value of 4.3.
4
How can I fix CVE-2020-21321 in emlog v6.0?
To fix CVE-2020-21321, it is recommended to update emlog v6.0 to the latest version or apply the official patch provided by the vendor.
5
Where can I find more information about CVE-2020-21321?
You can find more information about CVE-2020-21321 on the official GitHub page: https://github.com/emlog/emlog/issues/50