Home

Description

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the admin password without consent. Impact is account takeover of privileged users. Severity: High. As of time of publication, no known patched versions exist.

PUBLISHED Reserved 2025-10-03 | Published 2025-10-10 | Updated 2025-10-10 | Assigner GitHub_M




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Problem types

CWE-352: Cross-Site Request Forgery (CSRF)

Product status

<= pro-2.5.19
affected

References

github.com/.../emlog/security/advisories/GHSA-m2qw-9wjx-qxm2

cve.org (CVE-2025-61930)

nvd.nist.gov (CVE-2025-61930)

Download JSON