Emlog 是一个开源的网站构建系统。在 2.6.29 及之前版本中, 函数通过 提取所有 ZIP 条目时,未对条目路径进行校验以检测 路径遍历序列,仅对第一个条目的子目录结构进行了检查。攻击者可以利用该漏洞覆盖服务器文件系统中的任意文件,包括 ,从而实现即时远程代码执行(RCE)。在公告发布时,尚无公开已知的补丁。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53758 | 8.7 HIGH | Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized |
| CVE-2026-73848 | 6.9 MEDIUM | Emlog: Stored XSS via Tag Name in Article Editor |
| CVE-2026-53756 | 4.9 MEDIUM | Emlog Blind SQL Injection via Authentication Cookie |
No comments yet