Medium severity6.1NVD Advisory· Published Oct 3, 2025· Updated Jun 17, 2026
CVE-2025-60448
CVE-2025-60448
Description
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Emlog/Prodescription
Patches
Vulnerability mechanics
References
1- snowhy77.github.io/2025/08/21/SVG-File-Upload-XSS-Vulnerability-in-Emlog-Pro/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.