Improper input validation in Emlog Pro - CVE-2025-47787

 

Improper input validation in Emlog Pro - CVE-2025-47787

Published: April 9, 2026


Vulnerability identifier: #VU125572
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47787
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper input validation in /admin/store.php when downloading and installing remotely supplied ZIP plugin files. A remote user can send a specially crafted request with a malicious plugin archive URL to execute arbitrary code.

The issue occurs in the plugin installation functionality and requires access to initiate the remote plugin download request.


Affected software

Emlog Pro

How to mitigate CVE-2025-47787

Install security update from vendor's website.

Emlog Pro - update to 2.5.10

External References

Related Security Bulletins