PT-2025-36258 · Elunez · Eladmin
Aibot88
·
Published
2025-09-05
·
Updated
2025-09-05
·
CVE-2025-10014
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
elunez eladmin versions up to 2.7
Description
A flaw exists in elunez eladmin that impacts the
updateUserEmail function within the Email Address Handler component. Manipulation of the id/email argument in the /api/users/updateEmail/ API endpoint can lead to improper authorization. The attack may be performed remotely and is considered highly complex with difficult exploitability. The exploit has been published and requires knowledge of the RSA-encrypted password of the attacked user account.Recommendations
For versions up to 2.7, address the improper authorization issue by validating the
id/email argument in the updateUserEmail function of the Email Address Handler component.
Restrict access to the /api/users/updateEmail/ API endpoint until a resolution is implemented.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eladmin