216.73.217.174

CVE-2025-61318

· Published 08/12/2025 16:15 · Modified 09/12/2025 16:17

Labels: CVE-2025-61318 2025-12-08CVE-2025-61318CWE-24NVD-CWE-Other[email protected]

Essential information

Published
08/12/2025 16:15
Modified
09/12/2025 16:17
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CVSS metrics

Description

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
emlog / emlog cpe:2.3:a:emlog:emlog:2.5.20:*:*:*:pro:*:*:*

References