CVE-2025-47785
Last modified
CVE-2025-47785 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this will cause SQL injection to occur when the registered site is enabled, resulting in the injection of the admin account and password, which is then exploited by the backend remote code execution. As of time of publication, it is unknown whether a fix exists.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emlog | Emlog | <= 2.5.9 |
References
- https://github.com/emlog/emlog/security/advisories/GHSA-939m-47f7-m559Exploit, Vendor Advisory
- https://github.com/emlog/emlog/security/advisories/GHSA-939m-47f7-m559Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-47785?
How severe is CVE-2025-47785?
How do I fix CVE-2025-47785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4778A vulnerability was found in PHPGurukul Park Ticketing Manag…8.8
- CVE-2025-47780Asterisk is an open-source private branch exchange (PBX). Pr…7.8
- CVE-2025-47781Rallly is an open-source scheduling and collaboration tool. …9.8
- CVE-2025-47782motionEye is an online interface for the software motion, a …8.9
- CVE-2025-47783Label Studio is a multi-type data labeling and annotation to…6.1
- CVE-2025-47784Emlog is an open source website building system. Versions 2.…9.8
- CVE-2025-47786Emlog is an open source website building system. Version 2.5…4.8
- CVE-2025-47787Emlog is an open source website building system. Emlog Pro p…9.8
- CVE-2025-47788Atheos is a self-hosted browser-based cloud IDE. Prior to v6…9.4
- CVE-2025-47789Horilla is a free and open source Human Resource Management …6.1
- CVE-2025-4779lunary-ai/lunary versions prior to 1.9.24 are vulnerable to …6.1
- CVE-2025-47790Nextcloud Server is a self hosted personal cloud system. Nex…6.4
Are you affected by CVE-2025-47785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
