PT-2025-34143 · Elunez · Elunez Eladmin

Ez-Lbz

·

Published

2025-08-20

·

Updated

2025-08-21

·

CVE-2025-9239

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: elunez eladmin versions prior to 2.8
Description: A vulnerability exists in the EncryptUtils function within the DES Key Handler component of elunez eladmin. Manipulation of the STR PARAM argument with the input Passw0rd results in inadequate encryption strength. This issue can be exploited remotely and is considered to have high complexity, making exploitation difficult. The vulnerable function is located in the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java.
Recommendations: Update elunez eladmin to version 2.8 or later.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2025-9239

Affected Products

Elunez Eladmin