CVE-2025-62717
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-24

Last updated on: 2025-10-28

Assigner: GitHub, Inc.

Description
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-24
Last Modified
2025-10-28
Generated
2026-06-16
AI Q&A
2025-10-24
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
emlog emlog 2.5.23
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-NVD-CWE-noinfo
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in Emlog Pro version 2.5.23 is due to a session verification code error caused by a clearing logic error. It allows the verification code, which is supposed to be used only once for email verification, to be reused anywhere an email verification code is required.

Impact Analysis

The vulnerability could allow an attacker to reuse a verification code multiple times, potentially bypassing email verification steps. This could lead to unauthorized actions or access where email verification is required.

Mitigation Strategies

To mitigate this vulnerability, update Emlog Pro to a version that includes the fix from commit 1f726df, as this resolves the session verification code clearing logic error. Until the update is applied, avoid relying on email verification codes for critical security functions, as the verification code could be reused.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-62717. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart