Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
CVSS
No CVSS.
References
Configurations
No configuration.
History
11 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-11 20:16
Updated : 2026-03-12 21:08
NVD link : CVE-2026-31954
Mitre link : CVE-2026-31954
CVE.ORG link : CVE-2026-31954
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
