PT-2025-36437 · Elunez · Eladmin
Aibot88
·
Published
2025-09-08
·
Updated
2025-09-08
·
CVE-2025-10084
Aibot88
·
Published
2025-09-08
·
Updated
2025-09-08
·
CVE-2025-10084
4.3
Medium
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
elunez eladmin versions up to 2.7
Description:
A vulnerability exists in elunez eladmin that affects the `queryErrorLogDetail` function within the `SysLogController` component. The vulnerability is located in the file `/api/logs/error/1` and leads to improper authorization. It is possible to initiate the attack remotely.
Recommendations:
Versions prior to 2.8 should be updated.
As a temporary workaround, consider restricting access to the `/api/logs/error/1` API endpoint until a patch is available.
Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment