CVE-2021-31737: Malicious File Upload
Published May 6, 2021
·Updated
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
Affected Software
2 affected components
Emlog emlog=5.3.1
Emlog emlog=6.0.0
Event History
May 6, 2021
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-31737.
2
What is the severity of CVE-2021-31737?
The severity of CVE-2021-31737 is critical with a CVSS score of 9.8.
3
Which versions of Emlog are affected by CVE-2021-31737?
Emlog versions 5.3.1 and 6.0.0 are affected by CVE-2021-31737.
4
What is the cause of CVE-2021-31737?
CVE-2021-31737 is caused by a Remote Code Execution vulnerability due to the upload of a database backup file in admin/data.php.
5
Is there a fix available for CVE-2021-31737?
Currently, there is no known fix available for CVE-2021-31737. It is recommended to update to a patched version when it becomes available.