CVE-2025-29405: Malicious File Upload
Published Mar 19, 2025
·Updated
An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5. allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
2 affected components
Emlog Emlog Pro>=2.5.0<2.5.*
Emlog emlog>=2.5.1<=2.5.7
Event History
Mar 19, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29405?
CVE-2025-29405 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-29405?
To fix CVE-2025-29405, upgrade to a patched version of emlog pro that addresses the arbitrary file upload issue.
3
What versions of emlog pro are affected by CVE-2025-29405?
CVE-2025-29405 affects emlog pro versions 2.5.0 and 2.5.*.
4
What type of attack can be executed using CVE-2025-29405?
CVE-2025-29405 allows attackers to execute arbitrary code by uploading crafted PHP files.
5
Where can I find more information about CVE-2025-29405?
More information about CVE-2025-29405 can be found in security advisories and repositories discussing the vulnerability.