ELOG / Elog
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-64349 | ELOG user profile missing authorization | HIGH | 8.7 | Oct 31, 2025 |
| CVE-2025-64348 | ELOG configuration file authorization bypass | CRITICAL | 9.3 | Oct 31, 2025 |
| CVE-2025-62618 | ELOG file upload stored XSS | HIGH | 8.6 | Oct 31, 2025 |
| CVE-2019-3996 | ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests. | MEDIUM | 6.5 | Dec 17, 2019 |
| CVE-2019-3995 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash th… | HIGH | 7.5 | Dec 17, 2019 |
| CVE-2019-3994 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG ser… | HIGH | 7.5 | Dec 17, 2019 |
| CVE-2019-3993 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by se… | HIGH | 7.5 | Dec 17, 2019 |
| CVE-2019-3992 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration fi… | HIGH | 7.5 | Dec 17, 2019 |
| CVE-2016-6342 | elog 3.1.1 allows remote attackers to post data as any username in the logbook. | HIGH | 7.5 | Jun 27, 2017 |
| CVE-2008-7004 | Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c. | HIGH | 10.0 | Aug 19, 2009 |
| CVE-2008-0445 | The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via cra… | MEDIUM | 5.0 | Jan 24, 2008 |
| CVE-2008-0444 | Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext p… | MEDIUM | 4.3 | Jan 24, 2008 |
Showing 1 to 12 of 12 CVEs