MEDIUM
Emlog vulnerable to Deserialization of Untrusted Data
Published May 15, 2025
6.6
MEDIUMCVSS 4.0
EPSS 0.49%
Description
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return `false`. Commit 9643250802188b791419e3c2188577073256a8a2 fixes the issue.
Affected products
-
- Version <= 2.5.13StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/emlog/emlog/commit/9643250802188b791419e3c2188577073256a8a2 x_refsource_MISCPatch
- https://github.com/emlog/emlog/security/advisories/GHSA-f56g-m99v-mqc3 x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/emlog/emlog/commit/9643250802188b791419e3c2188577073256a8a2 | x_refsource_MISCPatch | |
| https://github.com/emlog/emlog/security/advisories/GHSA-f56g-m99v-mqc3 | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 15, 2025
Updated May 16, 2025
Reserved May 9, 2025
Link CVE-2025-47784
CISA Vulnrichment
Updated May 16, 2025