eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22978.json"
}{
"cpe": "cpe:2.3:a:eladmin:eladmin:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.7"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22978.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"301195117098250310172124194590346395928",
"22735469467028449368033316264584261200",
"246837469930884708434613466488157158037",
"66397763688500589790082899361649109567",
"176562378080634361508019743747316463372",
"46848041610301684406544023377728611716",
"273172363772874440919731794934771705679",
"206561432641583508997498164058473049155",
"138275494480876189381292757998930319399",
"161078823449046972295844040316590276239",
"134733225621229357472123928446868243532"
],
"threshold": 0.9
},
"id": "CVE-2025-22978-0a4959b6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elunez/eladmin/commit/d6a16e9afc0a3b96a56f1a24ed167e1beec6ce2f",
"target": {
"file": "eladmin-common/src/main/java/me/zhengjie/utils/FileUtil.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "306095752260306632210177723131154727610",
"length": 621
},
"id": "CVE-2025-22978-39300355",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elunez/eladmin/commit/d6a16e9afc0a3b96a56f1a24ed167e1beec6ce2f",
"target": {
"file": "eladmin-common/src/main/java/me/zhengjie/utils/FileUtil.java",
"function": "downloadExcel"
}
}
]
"2026-08-12T14:52:31Z"