Vulnerability Description
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emlog | Emlog | 2.5.23 |
Related Weaknesses (CWE)
References
- https://github.com/emlog/emlog/commit/1f726df0ce56a1bc6e8225dd95389974173bd0c0Patch
- https://github.com/emlog/emlog/security/advisories/GHSA-wwj4-ppfj-hcm6Vendor Advisory
FAQ
What is CVE-2025-62717?
CVE-2025-62717 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could b...
How severe is CVE-2025-62717?
CVE-2025-62717 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-62717?
Check the references section above for vendor advisories and patch information. Affected products include: Emlog Emlog.