CVE-2025-30372 HIGH

CVE-2025-30372: Emlog Pro contains an SQL injection vulnerability.

Vendor Emlog
Product emlog
Weakness CWE-89 · SQLi
Published March 28, 2025
Last update March 28, 2025

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by URL double encoding. This could result in potential leakage of sensitive information from the user database. Version pro-2.5.9 fixes the issue.

Key dates

02Disclosure timeline

March 28, 2025 CVE published
March 28, 2025 Record updated