CVE-2025-29401: Code Injection
Published Mar 19, 2025
·Updated
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
2 affected components
Emlog Emlog Pro
Emlog emlog=2.5.7
Event History
Mar 19, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29401?
CVE-2025-29401 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-29401?
To fix CVE-2025-29401, users should upgrade to the latest version of Emlog Pro that addresses this vulnerability.
3
What type of attacks can be exploited through CVE-2025-29401?
CVE-2025-29401 allows attackers to upload malicious PHP files, thereby executing arbitrary code on the server.
4
Who is affected by CVE-2025-29401?
CVE-2025-29401 affects users of Emlog Pro version 2.5.7 and possibly earlier versions.
5
What component is vulnerable in CVE-2025-29401?
The vulnerable component in CVE-2025-29401 is /views/plugin.php of Emlog Pro.