CVE-2020-21585: Malicious File Upload
Published Apr 2, 2021
·Updated
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
Affected Software
1 affected component
Emlog emlog=6.0.0
Event History
Apr 2, 2021
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-21585.
2
What is the severity of CVE-2020-21585?
The severity of CVE-2020-21585 is critical with a CVSS score of 9.8.
3
How does the vulnerability in emlog v6.0.0 allow users to upload webshells?
The vulnerability in emlog v6.0.0 allows users to upload webshells via the zip plugin module.
4
Which version of emlog is affected by this vulnerability?
Emlog version 6.0.0 is affected by this vulnerability.
5
Is there a fix available for CVE-2020-21585?
Yes, a fix for CVE-2020-21585 is available. It is recommended to update to the latest version of emlog.
6
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the GitHub issue links: [link1](https://github.com/emlog/emlog/issues/54) and [link2](https://github.com/pwnninja/emlog/issues/1).