CVE-2023-43291: Critical severity emlog vulnerability
Published Sep 26, 2023
·Updated
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
Affected Software
1 affected component
Emlog emlog<=2.1.15
Event History
Sep 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-43291.
2
What is the severity of CVE-2023-43291?
The severity of CVE-2023-43291 is critical with a CVSS score of 9.8.
3
How does the vulnerability CVE-2023-43291 occur?
The vulnerability CVE-2023-43291 occurs due to deserialization of untrusted data in emlog pro v.2.1.15 and earlier.
4
What is the impact of CVE-2023-43291?
The impact of CVE-2023-43291 is that it allows a remote attacker to execute arbitrary code via the cache.php component.
5
How can I fix CVE-2023-43291?
To fix CVE-2023-43291, it is recommended to update emlog pro to version 2.1.16 or later.