Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload .svg file that contains JavaScript code that is later being executed. Commit 052f9c4226b2c0014bcd857fec47677340b185b1 fixes the issue.
History

Mon, 06 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Description Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload .svg file that contains JavaScript code that is later being executed. Commit 052f9c4226b2c0014bcd857fec47677340b185b1 fixes the issue.
Title Emlog vulnerable to stored XSS in file upload functionality in emlog
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-06T17:16:13.290Z

Reserved: 2025-09-30T19:43:49.900Z

Link: CVE-2025-61769

cve-icon Vulnrichment

Updated: 2025-10-06T17:00:51.805Z

cve-icon NVD

Status : Received

Published: 2025-10-06T17:16:07.950

Modified: 2025-10-06T18:15:52.693

Link: CVE-2025-61769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.