Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-in administrator. The authentication cookie set in include/lib/loginauth.php has no explicit SameSite attribute, enabling Chrome's temporary Lax+POST grace window. The query_database case passes attacker-controlled sql and confirm_code values to Ai::queryDatabase in include/service/ai.php; read queries need no confirmation, write queries accept the public confirm string, only the blog table is write-protected, and aliasing password as pwd_hash bypasses output redaction. A successful request can read every database table and write every table except blog, including changing the user table to take over an administrator account. No fixed version is available as of this review.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused PoC for CVE-2026-73847 affecting emlog pro through 2.6.23. It contains three files: a detailed README, an HTML CSRF proof-of-concept, and a Bash script that demonstrates the impact chain directly. The exploit is not part of a larger framework. The core vulnerability is a missing CSRF defense on the emlog AI assistant endpoint /admin/ai.php?action=execute_tool, which accepts SQL execution requests on behalf of an authenticated admin. The repository documents that the endpoint relies on session cookies, lacks CSRF token validation, uses a predictable write-confirmation value (confirm), allows unrestricted reads, and permits writes to the user table. The README also describes a password-redaction bypass by aliasing the password column. The poc_csrf.html file is the browser-delivery component. It auto-submits a POST form to the vulnerable execute_tool endpoint with name=query_database, a JSON params field containing an INSERT INTO emlog_link SQL statement, and confirm_code=confirm. Its purpose is to prove that a cross-site page can induce an authenticated admin browser to execute arbitrary SQL during the effective SameSite/Lax+POST window. The poc_raw_impact.sh file is the direct exploitation component. It logs into the target admin interface using supplied credentials, stores cookies in /tmp files, queries the user table with SELECT uid, username, password AS pwd_hash FROM user to bypass output redaction, then overwrites uid=1's password hash using UPDATE user SET password='${NEWPASS_HASH}' WHERE uid=1 and confirm_code=confirm. Finally, it authenticates again with the attacker-chosen plaintext password HackedByPoC123! using a fresh cookie jar to prove successful admin takeover. Overall, the repository's purpose is to demonstrate both exploit delivery and exploit impact: the HTML file shows realistic CSRF delivery from a separate origin, while the Bash script isolates the vulnerable endpoint's capability to perform arbitrary SQL reads/writes and achieve full admin account takeover.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.