CVE-2025-44139: Malicious File Upload
Published Aug 1, 2025
·Updated
Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=uploadzip
Affected Software
2 affected components
Emlog Emlog Pro
Emlog emlog=2.5.7
Event History
Aug 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44139?
CVE-2025-44139 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-44139?
To fix CVE-2025-44139, ensure that file upload restrictions are implemented to prevent uploads of dangerous file types.
3
What types of attacks can CVE-2025-44139 enable?
CVE-2025-44139 can enable attackers to upload malicious files that could lead to remote code execution or server compromise.
4
Is CVE-2025-44139 easily exploitable?
Yes, CVE-2025-44139 is easily exploitable if the vulnerable version of Emlog Pro is accessible to attackers.
5
What version of Emlog Pro is affected by CVE-2025-44139?
Emlog Pro version 2.5.7 is affected by CVE-2025-44139, allowing for the unrestricted upload of files.