PT-2024-34570 · Eladmin · Eladmin

Shadia0

·

Published

2024-10-30

·

Updated

2025-05-17

·

CVE-2024-51242

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions eladmin versions 2.7 and earlier
Description A Server-Side Request Forgery (SSRF) issue has been identified. The manipulation of the HTTP Body ip parameter leads to SSRF. This occurs in the ServerDeployController.java file.
Recommendations For eladmin versions 2.7 and earlier, as a temporary workaround, consider restricting access to the ServerDeployController.java file until a patch is available. Avoid using the ip parameter in the affected HTTP Body until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-51242

Affected Products

Eladmin