PT-2025-36437 · Elunez · Eladmin
Aibot88
·
Published
2025-09-08
·
Updated
2025-09-08
·
CVE-2025-10084
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
elunez eladmin versions up to 2.7
Description
A vulnerability exists in elunez eladmin that affects the
queryErrorLogDetail function within the SysLogController component. The vulnerability is located in the file /api/logs/error/1 and leads to improper authorization. It is possible to initiate the attack remotely.Recommendations
Versions prior to 2.8 should be updated.
As a temporary workaround, consider restricting access to the
/api/logs/error/1 API endpoint until a patch is available.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eladmin