CVE-2024-12846: Emlog Pro link.php cross site scripting
Published Dec 21, 2024
·Updated
A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of the file /admin/link.php. The manipulation of the argument siteurl/icon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Emlog emlog<2.4.1
Event History
Dec 21, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12846?
CVE-2024-12846 is classified as a problematic vulnerability.
2
How do I fix CVE-2024-12846?
To fix CVE-2024-12846, you should update Emlog Pro to version 2.4.2 or later.
3
What type of vulnerability is CVE-2024-12846?
CVE-2024-12846 is a Cross-Site Scripting (XSS) vulnerability.
4
What is the affected software for CVE-2024-12846?
CVE-2024-12846 affects Emlog Pro versions up to 2.4.1.
5
What part of Emlog Pro is affected by CVE-2024-12846?
The vulnerability affects the file /admin/link.php, specifically the argument siteurl/icon.