shadia0

3 exploits Active since Oct 2024
CVE-2024-51242 WRITEUP MEDIUM WRITEUP
Eladmin < 2.7 - SSRF
A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.
CVSS 6.5
CVE-2024-51243 WRITEUP HIGH WRITEUP
Eladmin < 2.7 - Code Injection
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.
CVSS 7.2
CVE-2025-45809 WRITEUP MEDIUM WRITEUP
Litellm - SQL Injection
SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.
CVSS 5.4