Deserialization Vulnerability in Emlog Open Source Website Building System
CVE-2025-47784

6.6MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
15 May 2025

What is CVE-2025-47784?

Emlog, an open-source website building platform, is susceptible to a deserialization vulnerability found in versions 2.5.13 and earlier. This flaw allows an attacker to manipulate a crafted nickname, which can disrupt the normal operation of the str_replace function. Specifically, this manipulation may lead to the name_orig value being set to empty, resulting in failed deserialization and unintended behavior of the application. The vulnerability has been addressed in a commit that rectifies the issue and reinforces the security of the affected versions.

Affected Version(s)

emlog <= 2.5.13

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.