PT-2025-49559 · Emlog Pro · Emlog Pro

Published

2025-12-08

·

Updated

2025-12-09

·

CVE-2025-61318

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog Pro version 2.5.20
Description Emlog Pro 2.5.20 contains a flaw that allows for arbitrary file deletion. This issue is present in the admin/template.php and admin/plugin.php components, which do not properly validate file paths or filter potentially harmful code during deletion operations. This lack of validation enables attackers to perform directory traversal, potentially leading to unauthorized file deletion.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the admin/template.php and admin/plugin.php components.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-61318

Affected Products

Emlog Pro