A vulnerability was found in Emlog Pro 2.5.19. It has been declared as problematic. This affects an unknown function of the file /admin/setting.php?action=mail of the component Email Template Configuration. Such manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2025-60447. The attack can be executed remotely. There is not any exploit available.