漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
elunez eladmin Druid application-prod.yml default credentials
Vulnerability Description
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\src\main\resources\config\application-prod.yml of the component Druid. The manipulation of the argument login-username/login-password leads to use of default credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
CWE-1392
Vulnerability Title
ELADMIN 安全漏洞
Vulnerability Description
ELADMIN是elunez个人开发者的一个后台管理系统。 ELADMIN 2.7及之前版本存在安全漏洞,该漏洞源于使用默认凭据,攻击者可远程直接登录并泄露敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A