CVE-2025-30372
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-30372 is a newly disclosed SQL injection vulnerability affecting Emlog Pro versions 2.5.7 and 2.5.8. The issue arises due to the lack of proper encoding in `search_controller.php`. Specifically, the function fails to apply addslashes after urldecode, making it possible for attackers to bypass this security measure by employing URL double encoding. This flaw, if exploited, could potentially lead to the exposure of sensitive user data from the database. Emlog Pro users are advised to upgrade to version 2.5.9, which includes a patch to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Emlog
Affected Vendors
- EM Log