Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-61930


Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the admin password without consent. Impact is account takeover of privileged users. Severity: High. As of time of publication, no known patched versions exist.


Published

2025-10-10T20:15:38.803

Last Modified

2025-10-20T16:47:37.100

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emlog emlog ≤ 2.5.19 Yes

References