Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this will cause SQL injection to occur when the registered site is enabled, resulting in the injection of the admin account and password, which is then exploited by the backend remote code execution. As of time of publication, it is unknown whether a fix exists.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Emlog
Emlog emlog |
|
CPEs | cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:* | |
Vendors & Products |
Emlog
Emlog emlog |
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 15 May 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this will cause SQL injection to occur when the registered site is enabled, resulting in the injection of the admin account and password, which is then exploited by the backend remote code execution. As of time of publication, it is unknown whether a fix exists. | |
Title | EMLOG SQL Injection Vulnerability | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-15T19:29:23.499Z
Updated: 2025-05-19T14:35:52.539Z
Reserved: 2025-05-09T19:49:35.621Z
Link: CVE-2025-47785

Updated: 2025-05-19T14:35:45.485Z

Status : Analyzed
Published: 2025-05-15T20:16:08.947
Modified: 2025-06-12T16:39:17.467
Link: CVE-2025-47785

No data.