PT-2025-34143 · Elunez · Elunez Eladmin

·

CVE-2025-9239

·

Published

2025-08-20

·

Updated

2025-08-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions: elunez eladmin versions prior to 2.8
Description: A vulnerability exists in the EncryptUtils function within the DES Key Handler component of elunez eladmin. Manipulation of the STR PARAM argument with the input Passw0rd results in inadequate encryption strength. This issue can be exploited remotely and is considered to have high complexity, making exploitation difficult. The vulnerable function is located in the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java.
Recommendations: Update elunez eladmin to version 2.8 or later.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9239

Affected Products

Elunez Eladmin