CVE-2025-25827: SSRF
Published Feb 26, 2025
·Updated
A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.
Affected Software
2 affected components
Emlog Emlog Pro
Emlog emlog=2.5.4
Event History
Feb 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25827?
CVE-2025-25827 is considered a critical vulnerability due to its potential for allowing remote attackers to conduct unauthorized scans of local and internal systems.
2
How do I fix CVE-2025-25827?
To mitigate CVE-2025-25827, you should upgrade Emlog Pro to the latest version where this vulnerability has been patched.
3
What type of vulnerability is CVE-2025-25827?
CVE-2025-25827 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
4
Which software is affected by CVE-2025-25827?
CVE-2025-25827 affects Emlog Pro version 2.5.4.
5
What can attackers do exploiting CVE-2025-25827?
Exploiting CVE-2025-25827 allows attackers to perform port scans on internal and local services by submitting crafted URLs.