← Vulnerability feed

Vulnerability record · CVE-2025-62618 · published 31 October 2025

CVE-2025-62618: Elog project elog cross-site scripting vulnerability

Elog Project · Elog

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.

8.6 CVSS 4.0 High EPSS 0.30% · top 79.9% CWE-79 · Cross-site scriptingCWE-434 · Unrestricted file upload
8.6CVSS 4.0 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-62618 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-64349Elog project elog missing authorization vulnerabilityELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset…EPSS 0.35%7.5CVE-2019-3992Elog project elog information exposure vulnerabilityELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's config…EPSS 1.3%7.5CVE-2019-3993ELOG unauthenticated password hash disclosure via crafted HTTP POSTELOG 3.1.4-57bea22 and below exposes user password hashes to a remote attacker who sends a crafted HTTP POST request. No authentication or user inter…EPSS 46%analysed7.5CVE-2019-3994Elog project elog use after free vulnerabilityELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash th…EPSS 2.9%7.5CVE-2019-3995Elog project elog null pointer dereference vulnerabilityELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker ca…EPSS 29%7.5CVE-2016-6342Fedoraproject fedora improper access control vulnerabilityelog 3.1.1 allows remote attackers to post data as any username in the logbook.EPSS 1.0%7.1CVE-2025-64348Elog project elog missing authorization vulnerabilityELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifica…EPSS 0.30%6.5CVE-2019-3996Elog project elog vulnerabilityELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.EPSS 5.9%

Source: NIST National Vulnerability Database (record CVE-2025-62618), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.