CVE-2025-60447: XSS
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to persistent JavaScript execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60447?
CVE-2025-60447 is classified as a stored Cross-Site Scripting (XSS) vulnerability, which can lead to serious security risks if exploited.
How do I fix CVE-2025-60447?
To fix CVE-2025-60447, you should implement proper input sanitization and validation on the email template configuration component in Emlog Pro 2.5.19.
Who is affected by CVE-2025-60447?
CVE-2025-60447 affects all installations of Emlog Pro version 2.5.19 due to the vulnerable email template input functionality.
What impact does CVE-2025-60447 have on Emlog Pro users?
The impact of CVE-2025-60447 on Emlog Pro users includes the potential for attackers to execute unauthorized scripts, compromising user data and sessions.
When was CVE-2025-60447 discovered?
CVE-2025-60447 was discovered in August 2025.