Vulnerabilities
Vulnerable Software
Eladmin:  >> Eladmin  >> 2.7  Security Vulnerabilities
A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-10-30
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.
CVSS Score
7.2
EPSS Score
0.056
Published
2024-10-30
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
CVSS Score
4.8
EPSS Score
0.009
Published
2024-09-10
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-09-10
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file leads to path traversal: 'dir/../../filename'. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273551.
CVSS Score
5.5
EPSS Score
0.005
Published
2024-08-04


Contact Us

Shodan ® - All rights reserved