ID |
CVE-2025-60447
|
Sažetak |
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to persistent JavaScript execution. |
Reference |
|
CVSS |
Base: | 5.9 |
Impact: | 3.7 |
Exploitability: | 1.7 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
HIGH |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
LOW |
LOW |
LOW |
|
CVSS vektor |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L |
Zadnje važnije ažuriranje |
08-10-2025 - 15:25 |
Objavljeno |
03-10-2025 - 14:15 |