CVE-2025-9173: Emlog Pro media.php unrestricted upload
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The file upload in include/service/media.php verifies the file extension based on a list defined in include/lib/option.php. This whitelist prevents unrestricted uploads (e.g. PHP files). Therefore, the attack possibility is just of theoretical nature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9173?
The severity of CVE-2025-9173 is classified as critical due to the potential for unrestricted file uploads.
How do I fix CVE-2025-9173?
To fix CVE-2025-9173, upgrade Emlog Pro to version 2.5.19 or higher.
What systems are affected by CVE-2025-9173?
CVE-2025-9173 affects all versions of Emlog Pro up to and including 2.5.18.
What type of attack is possible with CVE-2025-9173?
An attacker can execute a remote attack to manipulate the upload functionality in Emlog Pro, leading to unauthorized file uploads.
Is CVE-2025-9173 exploitable remotely?
Yes, CVE-2025-9173 can be exploited remotely due to its nature of allowing remote file uploads.