CVE-2025-30372

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 28, 2025
Updated: Apr 14, 2025
CWE ID 89

Summary

CVE-2025-30372 is a newly disclosed SQL injection vulnerability affecting Emlog Pro versions 2.5.7 and 2.5.8. The issue arises due to the lack of proper encoding in `search_controller.php`. Specifically, the function fails to apply addslashes after urldecode, making it possible for attackers to bypass this security measure by employing URL double encoding. This flaw, if exploited, could potentially lead to the exposure of sensitive user data from the database. Emlog Pro users are advised to upgrade to version 2.5.9, which includes a patch to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share