CVE-2025-61930
EUVD-2025-3377610.10.2025, 20:15
Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the admin password without consent. Impact is account takeover of privileged users. Severity: High. As of time of publication, no known patched versions exist.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| emlog | emlog | 𝑥 ≤ 2.5.19 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration