CVE-CVE-2026-73847
Severity
MEDIUM
CVSS Score
6.8
Description
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-in administrator. The authentication cookie set in include/lib/loginauth.php has no explicit SameSite attribute, enabling Chrome's temporary Lax+POST grace window. The query_database case passes attacker-controlled sql a...
PoCs for CVE-CVE-2026-73847
CVE-2026-73847-emlog-PoC
SQL Injection
Shell
0
squeeze440
2026-08-16