Impact
The vulnerability in elunez eladmin allows an attacker to inject arbitrary system commands through the uploadPath argument used in App.java of the Application Deployment Module. This command injection flaw, classified as CWE-74 and CWE-77, enables an adversary to execute code with the privileges of the running application, potentially compromising system integrity and confidentiality.
Affected Systems
The flaw affects elunez eladmin versions up to and including 2.7. No other versions or products were specifically cited as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity risk. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog. However, remote exploitation is possible and public exploit code has been released, making it a realistic threat for exposed deployment interfaces.
OpenCVE Enrichment