Session Verification Code Issue in Emlog Pro Affects Open Source Web Building
CVE-2025-62717

2.7LOW

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
24 October 2025

What is CVE-2025-62717?

Emlog Pro, an open source website building system, has a vulnerability in version 2.5.23 related to improper session verification code handling. This flaw allows the possibility of reusing a verification code needed for email verification processes, which could potentially lead to unauthorized access and manipulation of user sessions. The issue has been addressed in a recent commit, enhancing the security of the application.

Affected Version(s)

emlog = 2.5.23

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.