CVE-2022-3968: emlog article_save.php cross site scripting
A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/articlesave.php. The manipulation of the argument tag leads to cross site scripting. The attack can be launched remotely. The name of the patch is 5bf7a79826e0ea09bcc8a21f69a0c74107761a02. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213547.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
emlog/admin/article_save.phpto a version that resolves this vulnerability.Patch 5bf7a79826e0ea09bcc8a21f69a0c74107761a02
Event History
Frequently Asked Questions
What is the vulnerability ID for this emlog vulnerability?
CVE-2022-3968
What is the severity of CVE-2022-3968?
CVE-2022-3968 has a severity of medium with a CVSS score of 6.1.
What software is affected by CVE-2022-3968?
CVE-2022-3968 affects Emlog with a version up to and exclusive of 2022-11-08.
What is the vulnerability type of CVE-2022-3968?
CVE-2022-3968 is a cross-site scripting (XSS) vulnerability.
How can the CVE-2022-3968 vulnerability be exploited?
CVE-2022-3968 can be exploited remotely by manipulating the 'tag' argument in the 'admin/article_save.php' file.