CVE-2025-25783: Malicious File Upload
Published Feb 26, 2025
·Updated
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.
Affected Software
2 affected components
Emlog pro
Emlog emlog=2.5.3
Event History
Feb 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25783?
CVE-2025-25783 has a high severity due to its ability to allow arbitrary code execution via an arbitrary file upload.
2
How do I fix CVE-2025-25783?
To fix CVE-2025-25783, update to the latest version of Emlog Pro that addresses this vulnerability.
3
What products are affected by CVE-2025-25783?
CVE-2025-25783 affects Emlog Pro version 2.5.3.
4
Can CVE-2025-25783 lead to a system compromise?
Yes, CVE-2025-25783 can lead to a system compromise if an attacker successfully uploads a malicious Zip file.
5
Is user input validation relevant to CVE-2025-25783?
Yes, inadequate user input validation is a contributing factor to the vulnerability described in CVE-2025-25783.