CVE-2020-21654: High severity emlog vulnerability
Published Oct 6, 2021
·Updated
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
Affected Software
1 affected component
Emlog emlog=6.0.0
Event History
Oct 6, 2021
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-21654.
2
What is the severity of CVE-2020-21654?
The severity of CVE-2020-21654 is high with a CVSS score of 7.2.
3
What is affected by CVE-2020-21654?
Emlog v6.0 is affected by CVE-2020-21654.
4
What is the description of CVE-2020-21654?
CVE-2020-21654 is a vulnerability in the component admin\template.php of Emlog v6.0, allowing attackers to getshell via a crafted Zip file.
5
Is there a reference for CVE-2020-21654?
Yes, you can find more information about CVE-2020-21654 in the following link: [https://github.com/emlog/emlog/issues/55](https://github.com/emlog/emlog/issues/55).