PT-2025-41601 · Emlog Pro · Emlog Pro

Snowhy77

·

Published

2025-10-10

·

Updated

2025-10-20

·

CVE-2025-61930

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog Pro versions 2.5.19 and earlier
Description Emlog Pro versions 2.5.19 and earlier are susceptible to a Cross-Site Request Forgery (CSRF) issue on the password change endpoint. This allows an attacker to trick a logged-in administrator into submitting a crafted POST request, leading to unauthorized password changes. Successful exploitation can result in account takeover of privileged users. CSRF is an attack where an authenticated user is tricked into performing unwanted actions on a web application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-61930
GHSA-M2QW-9WJX-QXM2

Affected Products

Emlog Pro