CVE-2025-47784 is a critical deserialization vulnerability affecting Emlog versions 2.5.13 and prior. An unauthenticated attacker can exploit this by crafting a malicious nickname, leading to a denial of service due to a failed deserialization process. With a CVSS score of 9.8, this vulnerability poses a significant risk for complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code or evidence of active exploitation, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.14CPE matchmatch criteria | cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.