CVE-2025-47784

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-47784
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47784.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47784
Aliases
  • GHSA-f56g-m99v-mqc3
Published
2025-05-15T20:16:08Z
Modified
2025-05-17T14:29:17.860230Z
Summary
[none]
Details

Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause str_replace to replace the value of name_orig with empty, causing deserialization to fail and return false. Commit 9643250802188b791419e3c2188577073256a8a2 fixes the issue.

References

Affected packages

Git / github.com/emlog/emlog

Affected ranges

Type
GIT
Repo
https://github.com/emlog/emlog
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

5.*

5.3.1

6.*

6.0.0
6.1.0

Other

ci

emlog_5.*

emlog_5.1.2
emlog_5.1.3
emlog_5.2.0
emlog_5.2.1
emlog_5.3.0

pro-1.*

pro-1.0.1
pro-1.0.2
pro-1.0.3
pro-1.0.4
pro-1.0.5
pro-1.0.6
pro-1.0.7
pro-1.0.8
pro-1.1.0
pro-1.1.1
pro-1.2.0
pro-1.2.1
pro-1.2.2
pro-1.3.0
pro-1.3.1
pro-1.4.0
pro-1.5.0
pro-1.5.0.new
pro-1.5.1
pro-1.6.0
pro-1.7.0
pro-1.7.1
pro-1.8.0
pro-1.9.0
pro-1.9.1
pro-1.9.2
pro-1.9.3

pro-2.*

pro-2.0.0
pro-2.0.1
pro-2.0.2
pro-2.0.3
pro-2.1.0
pro-2.1.1
pro-2.1.10
pro-2.1.11
pro-2.1.12
pro-2.1.13
pro-2.1.14
pro-2.1.15
pro-2.1.2
pro-2.1.3
pro-2.1.4
pro-2.1.5
pro-2.1.6
pro-2.1.7
pro-2.1.8
pro-2.1.9
pro-2.2.0
pro-2.2.1
pro-2.2.10
pro-2.2.11
pro-2.2.2
pro-2.2.3
pro-2.2.4
pro-2.2.5
pro-2.2.6
pro-2.2.7
pro-2.2.8
pro-2.2.9
pro-2.3.0
pro-2.3.1
pro-2.3.10
pro-2.3.11
pro-2.3.12
pro-2.3.13
pro-2.3.14
pro-2.3.15
pro-2.3.16
pro-2.3.17
pro-2.3.18
pro-2.3.2
pro-2.3.3
pro-2.3.4
pro-2.3.5
pro-2.3.6
pro-2.3.7
pro-2.3.8
pro-2.3.9
pro-2.4.0
pro-2.4.1
pro-2.4.2
pro-2.4.3
pro-2.5.1
pro-2.5.10
pro-2.5.11
pro-2.5.12
pro-2.5.13
pro-2.5.2
pro-2.5.3
pro-2.5.4
pro-2.5.5
pro-2.5.6
pro-2.5.7
pro-2.5.8
pro-2.5.9