PT-2025-13545 · Emlog Pro · Emlog Pro

0Ofo

·

Published

2025-03-28

·

Updated

2025-03-28

·

CVE-2025-30372

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog Pro versions pro-2.5.7 through pro-2.5.8
Description Emlog is an open source website building system. The issue arises from the search controller.php file not using addslashes after urldecode, allowing the preceding addslashes to be bypassed by URL double encoding. This could result in potential leakage of sensitive information from the user database.
Recommendations For Emlog Pro versions pro-2.5.7 and pro-2.5.8, update to version pro-2.5.9 to fix the issue. As a temporary workaround, consider restricting access to the search controller.php file until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30372
GHSA-W6XC-R6X5-M77C

Affected Products

Emlog Pro