{"api_version":"1","generated_at":"2026-07-23T12:11:07+00:00","cve":"CVE-2020-19028","urls":{"html":"https://cve.report/CVE-2020-19028","api":"https://cve.report/api/cve/CVE-2020-19028.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-19028","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-19028"},"summary":{"title":"CVE-2020-19028","description":"*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-06-05 21:15:00","updated_at":"2023-06-09 22:45:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://github.com/emlog/emlog","name":"https://github.com/emlog/emlog","refsource":"MISC","tags":[],"title":"GitHub - emlog/emlog: Emlog is a powerful blog and CMS system based on PHP and MySQL. We are committed to providing you with fast, stable, and extremely easy to use, comfortable content creation and site building services.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/sincere-c/CVE/issues/1","name":"https://github.com/sincere-c/CVE/issues/1","refsource":"MISC","tags":[],"title":"emlogcms has any file upload vulnerability · Issue #1 · sincere-c/CVE · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-19028","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-19028","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"19028","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emlog","cpe5":"emlog","cpe6":"6.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-19028","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/emlog/emlog","refsource":"MISC","name":"https://github.com/emlog/emlog"},{"refsource":"MISC","name":"https://github.com/sincere-c/CVE/issues/1","url":"https://github.com/sincere-c/CVE/issues/1"}]}},"nvd":{"publishedDate":"2023-06-05 21:15:00","lastModifiedDate":"2023-06-09 22:45:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emlog:emlog:6.0.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"19028","Ordinal":"180437","Title":"CVE-2020-19028","CVE":"CVE-2020-19028","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"19028","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}