PT-2025-40911 · Emlog · Emlog
Huu1J
·
Published
2025-10-06
·
Updated
2025-10-09
·
CVE-2025-61769
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Emlog versions up to and including 2.5.22
Description
A cross-site scripting (XSS) issue exists in Emlog, potentially allowing authenticated remote attackers to inject arbitrary web script or HTML. This is possible through the file upload functionality, specifically by uploading malicious .svg files containing JavaScript code which is then executed. The issue is addressed by commit 052f9c4226b2c0014bcd857fec47677340b185b1.
Recommendations
Update to a version later than 2.5.22.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emlog