CVE-2025-64349
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address,
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.
HIGH · CVSS 8.8
EPSS 0.00082
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0