CRITICAL🇵🇱 Wersja polska

CVE-2024-44677

CVSS 9.8v3.1pub. 2024-09-10upd. 2025-03-31

eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.

🤖 AI Analysis
How it works

An attacker sends a crafted HTTP request to the vulnerable DatabaseController.java component, forcing the server to execute requests to internal or external network resources (SSRF). This mechanism is then leveraged to escalate the attack and execute arbitrary code on the server side (RCE). The attack vector does not require authentication or user interaction, which significantly lowers the barrier to entry for the attacker.

Impact

An attacker can gain full control over the server — including confidentiality, integrity and availability of data (CVSS scores C:H/I:H/A:H). Arbitrary code execution, system takeover and access to internal network infrastructure are possible.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. It is recommended to update to a version newer than 2.7 and restrict access to DatabaseController-related endpoints at the firewall or reverse proxy level to trusted IP addresses.

Who is affected

Eladmin version 2.7 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Eladmin

    APP
    Eladmin
    ≤ 2.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESSRF
CWE
References

Related vulnerabilities

CVE-2025-22978CRITICAL9.8PL ✓same product

CSV Injection w module pobierania logów wyjątków — Eladmin

CVE-2024-51243HIGH7.2same product

The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all applicat...

CVE-2025-70997MEDIUM6.5same product

W eladmin w wersji 2.7 i wcześniejszych odkryto podatność pozwalającą na arbitralny reset hasła dowolnego użyt...

CVE-2025-9239MEDIUM6.3same product

A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function Enc...

CVE-2025-8530MEDIUM5.5same product

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by ...