CVE-2025-10014 LOW

CVE-2025-10014: elunez eladmin Email Address updateEmail updateUserEmail improper authorization

Vendor Elunez
Product eladmin
Weakness CWE-285
Published September 5, 2025
Last update September 5, 2025

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the argument id/email can lead to improper authorization. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been published and may be used. It is required to know the RSA-encrypted password of the attacked user account.

Key dates

02Disclosure timeline

September 5, 2025 CVE published
September 5, 2025 Record updated