Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.
The admin/template.php and admin/plugin.php components do not validate the path or filter dangerous characters in parameters passed to file deletion operations. An attacker can provide a crafted parameter containing path traversal sequences (e.g., '../'), which allows escaping the allowed directory and pointing to any file in the server's file system. As a result, the system performs a deletion operation on the file indicated by the attacker, rather than only on template or plugin files.
An attacker can delete any files accessible to the web server process, which may lead to data destruction, application configuration corruption, or complete service disruption (integrity and availability).
Apply patches available from the vendor according to the references. Until the update is applied, it is recommended to restrict access to the administration panel exclusively to trusted IP addresses and monitor file system operations on the server.
Emlog Pro version 2.5.20
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HEmlog
APPEmlog2.5.20
Related vulnerabilities
Emlog: nieautoryzowany upload pliku PHP przez REST API — RCE
RCE przez dowolne przesyłanie plików w Emlog Pro 2.5.7
Emlog Pro – dowolne przesyłanie plików umożliwiające RCE (admin/plugin.php)
Emlog Pro – arbitrary file upload umożliwiający RCE przez /admin/plugin.php
RCE przez arbitrary file upload w Emlog Pro — komponent /content/templates/