Home

Description

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.

PUBLISHED Reserved 2025-10-20 | Published 2025-10-24 | Updated 2025-10-24 | Assigner GitHub_M




LOW: 2.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

Problem types

CWE-287: Improper Authentication

Product status

= 2.5.23
affected

References

github.com/.../emlog/security/advisories/GHSA-wwj4-ppfj-hcm6

github.com/...ommit/1f726df0ce56a1bc6e8225dd95389974173bd0c0

cve.org (CVE-2025-62717)

nvd.nist.gov (CVE-2025-62717)

Download JSON