CVE-2025-62618

Source
https://cve.org/CVERecord?id=CVE-2025-62618
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62618.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62618
Published
2025-10-31T19:15:50.753Z
Modified
2026-04-10T05:33:58.126425Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.

References

Affected packages

Git / bitbucket.org/ritt/elog

Affected ranges

Type
GIT
Repo
https://bitbucket.org/ritt/elog
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
7092ff64f6eb9521f8cc8c52272a020bf3730946
Type
GIT
Repo
https://bitbucket.org/ritt/elog
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
f81e5695c40997322fe2713bfdeba459d9de09dc

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "3.1.5-20251014"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62618.json"