Impact
Eladmin through version 2.7 contains a missing authorization flaw in the LocalStorageController uploadPicture handler. Authenticated users with low privileges can send POST requests directly to "/api/localStorage/pictures" and exploit the handler to write image files into the server’s local storage directory. The action also discloses the absolute server path of the storage location, revealing sensitive file system information.
Affected Systems
All installations of Eladmin up to and including 2.7 are affected. The vulnerability is specific to the LocalStorageController component and can be exploited by any user that has a valid account but lacks the "storage:add" permission.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Although no EPSS data is available and this issue is not listed in the CISA KEV catalog, the attack requires only an authenticated session with low privileges and the path disclosure may assist further attacks. The vulnerability is likely exploitable in environments where the LocalStorageController endpoint is exposed and not properly protected by role‑based access controls.
OpenCVE Enrichment