PT-2025-21366 · Emlog · Emlog

Jilaqi2333

·

Published

2025-05-15

·

Updated

2025-05-15

·

CVE-2025-47786

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: Emlog version 2.5.13
Description: Emlog is an open source website building system with a stored cross-site scripting issue. This allows any registered user to construct malicious JavaScript, inducing all website users to click. The /admin/comment.php endpoint is affected, where the perpage num parameter is not validated and is directly stored in the database. The output is not filtered, resulting in the direct output of malicious code.
Recommendations: For Emlog version 2.5.13, as a temporary workaround, consider validating and filtering the perpage num parameter in the /admin/comment.php endpoint to prevent malicious code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-47786
GHSA-82QC-9VG7-2C6C

Affected Products

Emlog