← Back

Elog Project

elog_project

9 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Elog
elog

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elog Project
1Elog
Jun 17, 2026
Oct 31, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not confi...Show more
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.Show less
1Elog Project
1Elog
Jun 17, 2026
Oct 31, 2025
7.1 HIGH· v4
7.1 HIGH· v3
N/A· v2
ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS...Show more
ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.Show less
1Elog Project
1Elog
Jun 17, 2026
Oct 31, 2025
8.6 HIGH· v4
8.0 HIGH· v3
N/A· v2
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP re...Show more
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.Show less
2Elog Project
Fedoraproject
2Elog
Fedora
Jun 17, 2026
Dec 17, 2019
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.
2Elog Project
Fedoraproject
2Elog
Fedora
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request.
2Elog Project
Fedoraproject
2Elog
Fedora
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the E...Show more
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the ELOG function retrieve_url() to use a freed variable.Show less
2Elog Project
Fedoraproject
2Elog
Fedora
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request.
2Elog Project
Fedoraproject
2Elog
Fedora
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration...Show more
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG, passwords.Show less
2Elog Project
Fedoraproject
2Elog
Fedora
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
elog 3.1.1 allows remote attackers to post data as any username in the logbook.