CNNVD-202601-077 Information

CNNVD ID

CNNVD-202601-077

CVE-2026-21430

  • CNNVD Published: 2026-01-02

Description (Chinese)

emlog是emlog开源的一套基于PHP和MySQL的CMS建站系统。 emlog 2.5.23版本存在跨站请求伪造漏洞,该漏洞源于文章创建功能存在跨站请求伪造,可能导致用户被迫发布攻击者控制的文章。

Description (English)

Emlog is a CMS station system based on PHP and MySQL. Version 2.5.23 contains a breach of cross-site requests for forgery, which stems from the creation of cross-site requests for forgery, which may result in users being forced to publish articles controlled by the attackers.

Hazard Level

High

Vulnerability Type

跨站请求伪造

Affected Vendor

Emlog

Published

2026-01-02

Last Modified

2026-02-24

References

https://github.com/emlog/emlog/security/advisories/GHSA-2g2w-vmg7-pq4q https://access.redhat.com/security/cve/cve-2026-21430

Patch

https://github.com/emlog/emlog/releases

Share on: