CVE-2025-47784: Emlog vulnerable to Deserialization of Untrusted Data
Published May 15, 2025
·Updated
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause strreplace to replace the value of nameorig with empty, causing deserialization to fail and return false. Commit 9643250802188b791419e3c2188577073256a8a2 fixes the issue.
Affected Software
2 affected components
Emlog emlog<=2.5.13
Emlog emlog<2.5.14
Remediation
Event History
May 15, 2025
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47784?
CVE-2025-47784 has been classified as a moderate severity deserialization vulnerability.
2
How do I fix CVE-2025-47784?
To fix CVE-2025-47784, upgrade Emlog to version 2.5.14 or later.
3
What versions of Emlog are affected by CVE-2025-47784?
Emlog versions 2.5.13 and prior are affected by CVE-2025-47784.
4
What type of vulnerability is CVE-2025-47784?
CVE-2025-47784 is a deserialization vulnerability that can lead to unexpected behavior.
5
Who is affected by CVE-2025-47784?
Users of Emlog versions 2.5.13 and earlier are vulnerable to CVE-2025-47784.