Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
References
| Link | Resource |
|---|---|
| https://github.com/emlog/emlog/commit/1f726df0ce56a1bc6e8225dd95389974173bd0c0 | Patch |
| https://github.com/emlog/emlog/security/advisories/GHSA-wwj4-ppfj-hcm6 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-10-24 21:16
Updated : 2025-10-28 14:15
NVD link : CVE-2025-62717
Mitre link : CVE-2025-62717
CVE.ORG link : CVE-2025-62717
JSON object : View
Products Affected
emlog
- emlog
CWE
