CVE-2025-61599: Emlog is Vulnerable to Stored Cross-Site Scripting (XSS) in "Twitter" Feature via Markdown Input
Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21 and below. An authenticated user with privileges to post a "Twitter" message can inject arbitrary JavaScript code. The malicious script is stored on the server and gets executed in the browser of any user, including administrators, when they click on the malicious post to view it. This issue does not currently have a fix.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61599?
The severity of CVE-2025-61599 is considered high due to the potential for an attacker to execute arbitrary JavaScript code.
How do I fix CVE-2025-61599?
To fix CVE-2025-61599, update Emlog EMLOG Pro to version 2.5.22 or later, which addresses this security vulnerability.
Who is affected by CVE-2025-61599?
CVE-2025-61599 affects authenticated users of Emlog EMLOG Pro versions 2.5.21 and below with the capability to post Twitter messages.
What type of vulnerability is CVE-2025-61599?
CVE-2025-61599 is a stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-61599 be exploited without authentication?
No, CVE-2025-61599 requires authentication to exploit as it involves an authenticated user posting a Twitter message.