CVE-2018-18316

emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.