PT-2025-41601 · Emlog Pro · Emlog Pro

·

CVE-2025-61930

·

Published

2025-10-10

·

Updated

2025-10-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog Pro versions 2.5.19 and earlier
Description Emlog Pro versions 2.5.19 and earlier are susceptible to a Cross-Site Request Forgery (CSRF) issue on the password change endpoint. This allows an attacker to trick a logged-in administrator into submitting a crafted POST request, leading to unauthorized password changes. Successful exploitation can result in account takeover of privileged users. CSRF is an attack where an authenticated user is tricked into performing unwanted actions on a web application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61930
GHSA-M2QW-9WJX-QXM2

Affected Products

Emlog Pro