Description
A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the argument id/email can lead to improper authorization. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been published and may be used. It is required to know the RSA-encrypted password of the attacked user account.
INFO
Published Date :
2025-09-05T17:32:07.024Z
Last Modified :
2025-09-05T17:41:45.247Z
Source :
VulDB
AFFECTED PRODUCTS
The following products are affected by CVE-2025-10014 vulnerability.
Vendors | Products |
---|---|
Elunez |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-10014.