emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.