VYPR
leads to cross site scripting. It is possible to initiate the attack remotely","datePublished":"2022-04-29T08:15:07.003Z","dateModified":"2026-06-17T04:22:36.947Z","publisher":{"@type":"Organization","@id":"https://portal.vyprsec.ai#publisher","name":"VYPR","url":"https://portal.vyprsec.ai","logo":{"@type":"ImageObject","url":"https://portal.vyprsec.ai/icon.svg","width":64,"height":64},"description":"Real-time CVE intelligence newsroom — feeds, exploits, vendor advisories, and AI-synthesized insights."},"author":{"@type":"Organization","@id":"https://portal.vyprsec.ai#publisher","name":"VYPR","url":"https://portal.vyprsec.ai","logo":{"@type":"ImageObject","url":"https://portal.vyprsec.ai/icon.svg","width":64,"height":64},"description":"Real-time CVE intelligence newsroom — feeds, exploits, vendor advisories, and AI-synthesized insights."},"proficiencyLevel":"Expert","about":{"@type":"Thing","@id":"https://nvd.nist.gov/vuln/detail/CVE-2022-1526","name":"CVE-2022-1526","identifier":"CVE-2022-1526","description":"A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input leads to cross site scripting. It is possible to initiate the attack remotely but it requires a signup and login by the attacker. The exploit has been disclosed to the public and may be used.","additionalType":"https://schema.org/SoftwareApplication","sameAs":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1526"]},"keywords":"CVE-2022-1526, Low, CWE-79, Emlog Emlog, Emlog Emlog, Unspecified Emlog","mentions":[{"@type":"SoftwareApplication","name":"Emlog","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Emlog"}},{"@type":"SoftwareApplication","name":"Emlog","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Emlog"}},{"@type":"SoftwareApplication","name":"Emlog","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Unspecified"}}],"isAccessibleForFree":true},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://portal.vyprsec.ai/"},{"@type":"ListItem","position":2,"name":"CVEs","item":"https://portal.vyprsec.ai/cves"},{"@type":"ListItem","position":3,"name":"CVE-2022-1526","item":"https://portal.vyprsec.ai/cves/CVE-2022-1526"}]}]}
Low severity3.5NVD Advisory· Published Apr 29, 2022· Updated Jun 17, 2026

CVE-2022-1526

CVE-2022-1526

Description

A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input leads to cross site scripting. It is possible to initiate the attack remotely but it requires a signup and login by the attacker. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Emlog/Emlog2 versions
    cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:*+ 1 more
    • cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:*range: <=1.2.2
    • (no CPE)range: <=1.2.2
  • Unspecified/Emlogcpe-rescue
    Range: 1.2.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.