CVE-2025-64349: Elog Project Elog
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.
Affected products
- Elog Project Elog: up to and including 3.1.5-20251014
Published 2025-10-31. Last modified 2026-06-17.