CVE-2025-25818

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 3, 2025
CWE ID 79

Summary

CVE-2025-25818 is a newly disclosed cross-site scripting (XSS) vulnerability affecting Emlog Pro version 2.5.4. This issue permits attackers to inject malicious web scripts or HTML code into the postStrVar function located at article_save.php. Successful exploitation of this vulnerability could lead to unintended execution of attacker-supplied code in a user's browser, potentially resulting in data theft or unauthorized account access. Users are advised to upgrade to a patched version of Emlog Pro immediately to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share