Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elog Project
Elog Project elog |
|
| CPEs | cpe:2.3:a:elog_project:elog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Elog Project
Elog Project elog |
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elog
Elog elog |
|
| Vendors & Products |
Elog
Elog elog |
Fri, 31 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration. | |
| Title | ELOG user profile missing authorization | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-12-02T14:55:52.728Z
Reserved: 2025-10-30T20:40:39.301Z
Link: CVE-2025-64349
Updated: 2025-12-02T14:55:42.029Z
Status : Analyzed
Published: 2025-10-31T19:15:51.777
Modified: 2025-11-10T16:35:07.577
Link: CVE-2025-64349
No data.
OpenCVE Enrichment
Updated: 2025-11-03T10:43:51Z