PT-2025-21366 · Emlog · Emlog
Jilaqi2333
·
Published
2025-05-15
·
Updated
2025-05-15
·
CVE-2025-47786
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions:
Emlog version 2.5.13
Description:
Emlog is an open source website building system with a stored cross-site scripting issue. This allows any registered user to construct malicious JavaScript, inducing all website users to click. The
/admin/comment.php endpoint is affected, where the perpage num parameter is not validated and is directly stored in the database. The output is not filtered, resulting in the direct output of malicious code.Recommendations:
For Emlog version 2.5.13, as a temporary workaround, consider validating and filtering the
perpage num parameter in the /admin/comment.php endpoint to prevent malicious code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emlog