PT-2025-43672 · Emlog+1 · Emlog+1
Published
2025-10-24
·
Updated
2025-10-24
·
CVE-2025-62717
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Emlog versions prior to the commit 1f726df
Emlog Pro version 2.5.23
Description
Emlog Pro version 2.5.23 contains a flaw related to session verification codes. A clearing logic error allows the reuse of email verification codes in any context where they are required.
Recommendations
Update to a version with the fix included in commit 1f726df.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emlog
Emlog Pro