CVE-2021-3293

emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emlog:emlog:5.3.1:*:*:*:*:*:*:*

History

20 Mar 2023, 20:31

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 5.3
CWE CWE-22 NVD-CWE-noinfo

09 Feb 2021, 21:07

Type Values Removed Values Added
References (MISC) https://github.com/thinkgad/Bugs/blob/main/emlog%20v5.3.1%20has%20Full%20Path%20Disclosure%20vulnerability.md - (MISC) https://github.com/thinkgad/Bugs/blob/main/emlog%20v5.3.1%20has%20Full%20Path%20Disclosure%20vulnerability.md - Exploit, Third Party Advisory
References (MISC) https://github.com/emlog/emlog/issues/62 - (MISC) https://github.com/emlog/emlog/issues/62 - Exploit, Third Party Advisory
CWE CWE-22
CPE cpe:2.3:a:emlog:emlog:5.3.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

08 Feb 2021, 15:31

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-08 15:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-3293

Mitre link : CVE-2021-3293

CVE.ORG link : CVE-2021-3293


JSON object : View

Products Affected

emlog

  • emlog