2.1
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P
Description
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload .svg file that contains JavaScript code that is later being executed. Commit 052f9c4226b2c0014bcd857fec47677340b185b1 fixes the issue.
Basic Information
ID
CVE-2025-61769
Source
GitHub_M
Published
Oct 6, 2025 at 16:09
Modified
Oct 6, 2025 at 17:16
Affected Product
Vendor
emlog
Product
emlog
Version
<= 2.5.22
Affected Versions
emlog emlog <= 2.5.22