Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This insufficient validation allows attackers to execute arbitrary code on the vulnerable system. Version 2.5.10 contains a patch for the issue.
History

Tue, 01 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Emlog
Emlog emlog
CPEs cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:*
Vendors & Products Emlog
Emlog emlog
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 15 May 2025 19:45:00 +0000

Type Values Removed Values Added
Description Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This insufficient validation allows attackers to execute arbitrary code on the vulnerable system. Version 2.5.10 contains a patch for the issue.
Title Emlog Pro Contains a File Upload Vulnerability
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-15T19:27:03.663Z

Updated: 2025-05-19T14:34:51.439Z

Reserved: 2025-05-09T19:49:35.621Z

Link: CVE-2025-47787

cve-icon Vulnrichment

Updated: 2025-05-19T14:34:45.762Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:16:09.220

Modified: 2025-07-01T14:42:21.900

Link: CVE-2025-47787

cve-icon Redhat

No data.