Vulnerabilities
Vulnerable Software
Eladmin:  >> Eladmin  >> 2.7  Security Vulnerabilities
A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
4.3
EPSS Score
0.001
Published
2025-04-04
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserialization. The attack may be launched remotely.
CVSS Score
4.7
EPSS Score
0.002
Published
2025-03-27
eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-02-03
A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-10-30
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.
CVSS Score
7.2
EPSS Score
0.026
Published
2024-10-30
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
CVSS Score
4.8
EPSS Score
0.004
Published
2024-09-10
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVSS Score
9.8
EPSS Score
0.003
Published
2024-09-10
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file leads to path traversal: 'dir/../../filename'. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273551.
CVSS Score
5.5
EPSS Score
0.006
Published
2024-08-04


Contact Us

Shodan ® - All rights reserved