CVE-2024-46540: Medium severity emlog pro vulnerability
Published Sep 30, 2024
·Updated
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.
Affected Software
2 affected components
Emlog Emlog Pro<2.3.15
Emlog emlog<2.3.15
Event History
Sep 30, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46540?
CVE-2024-46540 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2024-46540?
To fix CVE-2024-46540, upgrade Emlog Pro to version 2.3.15 or later.
3
What component is affected by CVE-2024-46540?
CVE-2024-46540 affects the /admin/store.php component of Emlog Pro.
4
Can CVE-2024-46540 lead to data breaches?
Yes, CVE-2024-46540 can allow attackers to upload webshells, potentially leading to data breaches.
5
Who is affected by CVE-2024-46540?
All users of Emlog Pro versions prior to 2.3.15 are affected by CVE-2024-46540.