PT-2025-36258 · Elunez · Eladmin

Aibot88

·

Published

2025-09-05

·

Updated

2025-09-05

·

CVE-2025-10014

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions elunez eladmin versions up to 2.7
Description A flaw exists in elunez eladmin that impacts the updateUserEmail function within the Email Address Handler component. Manipulation of the id/email argument in the /api/users/updateEmail/ API endpoint can lead to improper authorization. The attack may be performed remotely and is considered highly complex with difficult exploitability. The exploit has been published and requires knowledge of the RSA-encrypted password of the attacked user account.
Recommendations For versions up to 2.7, address the improper authorization issue by validating the id/email argument in the updateUserEmail function of the Email Address Handler component. Restrict access to the /api/users/updateEmail/ API endpoint until a resolution is implemented.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10014

Affected Products

Eladmin