Vulnerability Description
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emlog | Emlog | < 2.3.15 |
Related Weaknesses (CWE)
References
- https://gist.github.com/microvorld/1c1ef9c3390a5d88a5ede9f9424a8bd2Third Party Advisory
- https://github.com/emlog/emlogProduct
- https://github.com/microvorld/CVE-2024/blob/main/emlog.mdExploitThird Party Advisory
FAQ
What is CVE-2024-46540?
CVE-2024-46540 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells t...
How severe is CVE-2024-46540?
CVE-2024-46540 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46540?
Check the references section above for vendor advisories and patch information. Affected products include: Emlog Emlog.