Cross-Site Scripting Vulnerability in Emlog Product by Emlog Team
CVE-2025-5886
Key Information:
Badges
What is CVE-2025-5886?
A significant cross-site scripting vulnerability exists in Emlog versions up to 2.5.7, particularly affecting the processing of the /admin/article.php file. This issue allows attackers to manipulate the 'active_post' parameter, potentially leading to unauthorized script execution in the context of the user's browser. The vulnerability can be exploited remotely, posing a substantial risk since it allows attackers to execute malicious scripts without requiring user interaction. Given the public disclosure of this exploit, it is imperative for users to review their security measures and apply the necessary updates.
Affected Version(s)
Emlog 2.5.0
Emlog 2.5.1
Emlog 2.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved