PT-2025-34143 · Elunez · Elunez Eladmin
Ez-Lbz
·
Published
2025-08-20
·
Updated
2025-08-21
·
CVE-2025-9239
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
elunez eladmin versions prior to 2.8
Description:
A vulnerability exists in the
EncryptUtils function within the DES Key Handler component of elunez eladmin. Manipulation of the STR PARAM argument with the input Passw0rd results in inadequate encryption strength. This issue can be exploited remotely and is considered to have high complexity, making exploitation difficult. The vulnerable function is located in the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java.Recommendations:
Update elunez eladmin to version 2.8 or later.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elunez Eladmin