Aller au contenu

Fiche vulnérabilité

CVE-2025-61930 : faille élevée emlog emlog (CVSS 8.8)

Description

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the admin password without consent. Impact is account takeover of privileged users. Severity: High. As of time of publication, no known patched versions exist.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
10 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • emlog emlog

Références

Rechercher une autre vulnérabilité dans la base CVE