CRITICAL🇵🇱 Wersja polska

CVE-2025-61318

CVSS 9.1v3.1pub. 2025-12-08upd. 2025-12-09

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

🤖 AI Analysis
How it works

The admin/template.php and admin/plugin.php components do not validate the path or filter dangerous characters in parameters passed to file deletion operations. An attacker can provide a crafted parameter containing path traversal sequences (e.g., '../'), which allows escaping the allowed directory and pointing to any file in the server's file system. As a result, the system performs a deletion operation on the file indicated by the attacker, rather than only on template or plugin files.

Impact

An attacker can delete any files accessible to the web server process, which may lead to data destruction, application configuration corruption, or complete service disruption (integrity and availability).

Mitigation & patch

Apply patches available from the vendor according to the references. Until the update is applied, it is recommended to restrict access to the administration panel exclusively to trusted IP addresses and monitor file system operations on the server.

Who is affected

Emlog Pro version 2.5.20

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Emlog

    APP
    Emlog
    2.5.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-22799CRITICAL9.3PL ✓same product

Emlog: nieautoryzowany upload pliku PHP przez REST API — RCE

CVE-2025-29401CRITICAL9.8PL ✓same product

RCE przez dowolne przesyłanie plików w Emlog Pro 2.5.7

CVE-2025-25783CRITICAL9.8PL ✓same product

Emlog Pro – dowolne przesyłanie plików umożliwiające RCE (admin/plugin.php)

CVE-2023-44974CRITICAL9.8PL ✓same product

Emlog Pro – arbitrary file upload umożliwiający RCE przez /admin/plugin.php

CVE-2023-44973CRITICAL9.8PL ✓same product

RCE przez arbitrary file upload w Emlog Pro — komponent /content/templates/