PoC Index

CVE-2025-10014

LOW 3.1EPSS 0.3%

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the argument id/email can lead to improper authorization. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been published and may be used. It is required to know the RSA-encrypted password of the attacked user account. In elunez eladmin bis 2.7 ist eine Schwachstelle entdeckt worden. Betroffen davon ist die Funktion updateUserEmail der Datei /api/users/updateEmail/ der Komponente Email Address Handler. Die Manipulation des Arguments id/email führt zu improper authorization. Umgesetzt werden kann der Angriff über das Netzwerk. Ein Angriff erfordert eine vergleichsweise hohe Komplexität. Sie ist schwierig auszunutzen. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.

CVSS v4.0
1.3 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
3.1 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0
2.1 LOWAV:N/AC:H/Au:S/C:N/I:P/A:N
EPSS
0.28% chance of exploitation in the next 30 days, 20th percentile
Published
2025-09-05

Proof-of-concept exploits (1)

References

Related