Description
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
Problem types
CWE-287: Improper Authentication
Product status
References
github.com/.../emlog/security/advisories/GHSA-wwj4-ppfj-hcm6
github.com/...ommit/1f726df0ce56a1bc6e8225dd95389974173bd0c0