Emlog · Emlog · CVE-2025-5886
**Name of the Vulnerable Software and Affected Versions**
Emlog versions up to 2.5.7
**Description**
A problem was found in the processing of the file /admin/article.php, where the manipulation of the `active post` argument leads to cross-site scripting attacks. These attacks can be initiated remotely. The issue has been publicly disclosed and may be exploited.
**Recommendations**
For Emlog versions up to 2.5.7, consider disabling the `active post` argument in the /admin/article.php file as a temporary workaround until a patch is available. Restrict access to the /admin/article.php file to minimize the risk of exploitation. Avoid using the `active post` argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.