Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: plasma5Packages.ksystemlog

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-31954
0.0 NONE
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 1 week, 3 days ago
Emlog asynchronous media file deletion missing CSRF protection

Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

Affected products

emlog
  • ==<= 2.6.6

Matching in nixpkgs

Package maintainers