CVE 2.7 LOW

Emlog Pro session verification code error due to clearing logic error_CVE-2025-62717

2.7 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

Description

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.

Basic Information

ID CVE-2025-62717
Source GitHub_M
Published Oct 24, 2025 at 20:13
Modified Oct 24, 2025 at 20:34

Affected Product

Vendor emlog
Product emlog
Version = 2.5.23
Affected Versions emlog emlog = 2.5.23

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.