Path Traversal Vulnerability in Code-Projects Email Logging Interface 2.0
CVE-2025-13199
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 15 November 2025
Badges
What is CVE-2025-13199?
A path traversal vulnerability exists in the Email Logging Interface 2.0 developed by Code-Projects, specifically within the 'signup.cpp' file. This issue arises from improper handling of the 'Username' argument, allowing attackers with local access to manipulate file paths. This could potentially lead to unauthorized access and exposure of sensitive data. The exploit has been made public and poses a risk to environments where this software is deployed.
Affected Version(s)
Email Logging Interface 2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
