CVE-2025-64349: Elog Project Elog

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.

Affected products

Published 2025-10-31. Last modified 2026-06-17.