CVE-2025-64349 - ELOG user profile missing authorization
CVE ID : CVE-2025-64349
Published : 31 oktober 2025 19:15 | 1 uur, 11 minuten ago
Description : ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : 31 oktober 2025 19:15 | 1 uur, 11 minuten ago
Description : ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...