Metrics
Affected Vendors & Products
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elunez
Elunez eladmin |
|
| Vendors & Products |
Elunez
Elunez eladmin |
Wed, 20 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The manipulation of the argument STR_PARAM with the input Passw0rd leads to inadequate encryption strength. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. | |
| Title | elunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryption | |
| Weaknesses | CWE-310 CWE-326 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-20T18:02:08.454Z
Updated: 2025-08-20T18:46:33.829Z
Reserved: 2025-08-20T11:06:57.889Z
Link: CVE-2025-9239
Updated: 2025-08-20T18:46:27.154Z
Status : Awaiting Analysis
Published: 2025-08-20T18:15:37.280
Modified: 2025-08-22T18:09:17.710
Link: CVE-2025-9239
No data.