CVE-2025-29401
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-29401 is a critical vulnerability affecting the component /views/plugin.php in emlog pro v2.5.7. This issue enables attackers to upload crafted PHP files, resulting in arbitrary code execution. The vulnerability poses a significant risk as an unauthenticated attacker can exploit it to gain administrative control over the system. Successful exploitation could lead to data theft, unauthorized access, or even system takeover. Users of emlog pro v2.5.7 are strongly advised to upgrade to a patched version or apply the necessary security measures to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.