CVE-2025-10014

Source
https://cve.org/CVERecord?id=CVE-2025-10014
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10014.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-10014
Published
2025-09-05T18:15:37.450Z
Modified
2026-04-10T05:20:23.329838Z
Severity
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the argument id/email can lead to improper authorization. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been published and may be used. It is required to know the RSA-encrypted password of the attacked user account.

References

Affected packages

Git / github.com/elunez/eladmin

Affected ranges

Type
GIT
Repo
https://github.com/elunez/eladmin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.7"
        }
    ]
}

Affected versions

v2.*
v2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10014.json"