Aller au contenu

Fiche vulnérabilité

CVE-2025-53923 : faille moyenne emlog emlog (CVSS 6.1)

Description

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keyword parameter. If one persuades an user into clicking into prepared link it is possible to execute any JS code in admin's browser. As of time of publication, no known patched versions exist.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
16 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • emlog emlog

Références

Rechercher une autre vulnérabilité dans la base CVE