CNNVD-202510-777 Information

CNNVD ID

CNNVD-202510-777

CVE-2025-61769

  • CNNVD Published: 2025-10-06

Description (Chinese)

emlog是emlog开源的一套基于PHP和MySQL的CMS建站系统。 Emlog 2.5.22及之前版本存在安全漏洞,该漏洞源于文件上传功能未验证输入,可能导致跨站脚本攻击。

Description (English)

Emlog is a CMS station system based on PHP and MySQL. There is a security loophole in the Emlog 2.5.22 and previous versions, which stems from the unverified input of the document upload function, which may result in a cross-site script attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Emlog

Published

2025-10-06

Last Modified

2026-02-24

References

https://github.com/emlog/emlog/commit/052f9c4226b2c0014bcd857fec47677340b185b1 https://github.com/emlog/emlog/security/advisories/GHSA-rrf5-pv68-gpjf

Share on: