Vulnerabilities > Eladmin

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-44676 Cross-site Scripting vulnerability in Eladmin 2.7
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController.
network
low complexity
eladmin CWE-79
4.8
2024-09-10 CVE-2024-44677 Server-Side Request Forgery (SSRF) vulnerability in Eladmin 2.7
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
network
low complexity
eladmin CWE-918
critical
9.8
2024-08-04 CVE-2024-7458 Path Traversal vulnerability in Eladmin 2.7
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical.
network
low complexity
eladmin CWE-22
critical
9.8