CVE-2025-61597
03.10.2025, 07:15
Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored crosssite scripting (XSS) via the mail template settings. Once a malicious payload is saved, any subsequent visit to the settings page in an authenticated admin context will execute attackercontrolled JavaScript, enabling session/token theft and full admin account takeover. This issue is fixed in version 2.5.22.
Awaiting analysis
This vulnerability is currently awaiting analysis.