CVE-2024-5044

Source
https://cve.org/CVERecord?id=CVE-2024-5044
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5044.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-5044
Published
2024-05-17T11:31:05Z
Modified
2026-08-12T03:51:30Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Emlog Pro Cookie improper authentication
Details

A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. The manipulation of the argument AuthCookie leads to improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-264741 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5044.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.3.4"
                },
                {
                    "last_affected": "2.3.4"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/emlog/emlog

Affected ranges

Type
GIT
Repo
https://github.com/emlog/emlog
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:emlog:emlog:2.3.4:*:*:*:pro:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.3.4"
        },
        {
            "last_affected": "2.3.4"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.3.4
pro-2.*
pro-2.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5044.json"