CVE-2025-60448: XSS
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60448?
CVE-2025-60448 is classified as a medium severity stored Cross-Site Scripting (XSS) vulnerability affecting Emlog Pro 2.5.19.
How do I fix CVE-2025-60448?
To fix CVE-2025-60448, ensure proper validation and sanitization of SVG file uploads in the /admin/media.php component.
Which versions of Emlog Pro are affected by CVE-2025-60448?
CVE-2025-60448 affects Emlog Pro versions prior to 2.5.19.
What type of attack is possible with CVE-2025-60448?
CVE-2025-60448 allows attackers to execute stored JavaScript code via malicious SVG files.
Where can I find more details about CVE-2025-60448?
Further details about CVE-2025-60448 can be found in the related security advisories and vulnerability databases.