CVE-2024-51242

A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.
CVSS

No CVSS.

References
Link Resource
https://github.com/shadia0/Patienc/blob/main/eladmin_ssrf.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eladmin:eladmin:*:*:*:*:*:*:*:*

History

17 May 2025, 01:40

Type Values Removed Values Added
References () https://github.com/shadia0/Patienc/blob/main/eladmin_ssrf.md - () https://github.com/shadia0/Patienc/blob/main/eladmin_ssrf.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:eladmin:eladmin:*:*:*:*:*:*:*:*
First Time Eladmin
Eladmin eladmin

30 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 21:15

Updated : 2025-05-17 01:40


NVD link : CVE-2024-51242

Mitre link : CVE-2024-51242


JSON object : View

Products Affected

eladmin

  • eladmin
CWE

No CWE.