PT-2025-31877 · Elunez · Elunez Eladmin

Zast.Ai

·

Published

2025-08-04

·

Updated

2025-09-12

·

CVE-2025-8530

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions elunez eladmin versions up to 2.7
Description A problematic issue has been identified in elunez eladmin. The vulnerability involves the use of default credentials due to the manipulation of the login-username and login-password arguments within the file eladmin-systemsrcmainresourcesconfigapplication-prod.yml related to the Druid component. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 2.8: Address the issue by changing the default credentials for the Druid component. Versions prior to 2.8: Review and secure the configuration file eladmin-systemsrcmainresourcesconfigapplication-prod.yml to prevent the use of default credentials. Versions prior to 2.8: Restrict access to the login-username and login-password arguments to prevent unauthorized manipulation.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-8530

Affected Products

Elunez Eladmin