CVE-2025-62717: Emlog Pro session verification code error due to clearing logic error
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62717?
CVE-2025-62717 has a medium severity rating due to the session verification code error that can be exploited.
How do I fix CVE-2025-62717?
To fix CVE-2025-62717, upgrade Emlog Pro to version 2.5.24 or later where the vulnerability is patched.
What type of vulnerability is CVE-2025-62717?
CVE-2025-62717 is a session verification code flaw caused by a logic error in the application.
What is the impact of exploiting CVE-2025-62717?
Exploitation of CVE-2025-62717 allows attackers to reuse verification codes potentially leading to unauthorized access.
Which versions of Emlog Pro are affected by CVE-2025-62717?
CVE-2025-62717 specifically affects Emlog Pro version 2.5.23.