216.73.216.133

CVE-2025-8530

· Published 04/08/2025 23:15 · Modified 05/08/2025 16:15

Labels: CVE-2025-8530 2025-08-04CVE-2025-8530CWE-1392[email protected]

Essential information

Published
04/08/2025 23:15
Modified
05/08/2025 16:15
Author
Creator
CVSS
5.5 MEDIUM (v3) 5.5 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\src\main\resources\config\application-prod.yml of the component Druid. The manipulation of the argument login-username/login-password leads to use of default credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
elunez / eladmin cpe:2.3:a:elunez:eladmin:2.7:*:*:*:*:*:*:*
druid / druid cpe:2.3:a:druid:druid:*:*:*:*:*:*:*:*

References