Description
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file leads to path traversal: 'dir/../../filename'. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273551.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48379 | A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file leads to path traversal: 'dir/../../filename'. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273551. |
References
History
Tue, 06 Aug 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eladmin
Eladmin eladmin |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:eladmin:eladmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eladmin
Eladmin eladmin |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-05T14:55:41.487Z
Reserved: 2024-08-04T06:10:07.911Z
Link: CVE-2024-7458
Updated: 2024-08-05T14:52:10.664Z
Status : Analyzed
Published: 2024-08-04T22:15:50.837
Modified: 2024-08-06T17:12:28.250
Link: CVE-2024-7458
No data.
OpenCVE Enrichment
No data.
EUVD