CVE-2024-13140: Emlog Pro Cover Upload article.php cross site scripting
A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.3. Affected is an unknown function of the file /admin/article.php?action=uploadcover of the component Cover Upload Handler. The manipulation of the argument image leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13140?
CVE-2024-13140 is classified as problematic due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-13140?
To fix CVE-2024-13140, upgrade Emlog Pro to a version later than 2.4.3 where the vulnerability is patched.
What components are affected by CVE-2024-13140?
CVE-2024-13140 affects the Cover Upload Handler functionality in Emlog Pro up to version 2.4.3.
What is the exploit vector for CVE-2024-13140?
The exploit vector for CVE-2024-13140 involves manipulating the image argument in the /admin/article.php?action=upload_cover file.
Who is impacted by CVE-2024-13140?
Users of Emlog Pro versions 2.4.0 to 2.4.3 are at risk of exploitation due to CVE-2024-13140.