CVE-2025-47787 Details
Description
Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This insufficient validation allows attackers to execute arbitrary code on the vulnerable system. Version 2.5.10 contains a patch for the issue.
A file upload vulnerability has been identified in Emlog Pro versions prior to 2.5.10. The issue resides in the store.php component, which improperly validates the contents of remotely downloaded ZIP plugin files. This lack of adequate validation enables attackers to execute arbitrary code on the affected system.
Users can upgrade to Emlog Pro version 2.5.10 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/emlog/emlog/security/advisories/GHSA-4mcj-8gvh-p753 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/emlog/emlog/commit/691c13e90df2fb35e120f4e0735078bad018eed7 | [email protected] | Patch |
| https://github.com/emlog/emlog/security/advisories/GHSA-4mcj-8gvh-p753 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| emlog emlog | < 2.5.10 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2025 | Initial Analysis | [email protected] |
| May 19, 2025 | CVE Modified | CISA-ADP |
| May 15, 2025 | New CVE Received | [email protected] |