CVE 2.1 LOW

Emlog vulnerable to stored XSS in file upload functionality in emlog_CVE-2025-61769

2.1 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P

Description

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload .svg file that contains JavaScript code that is later being executed. Commit 052f9c4226b2c0014bcd857fec47677340b185b1 fixes the issue.

Basic Information

ID CVE-2025-61769
Source GitHub_M
Published Oct 6, 2025 at 16:09
Modified Oct 6, 2025 at 17:16

Affected Product

Vendor emlog
Product emlog
Version <= 2.5.22
Affected Versions emlog emlog <= 2.5.22

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.