CVE-2024-44676

MEDIUM

eladmin <2.7 - XSS

Title source: llm
STIX 2.1

Description

eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.

Scores

CVSS v3 4.8
EPSS 0.0091
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
eladmin/eladmin < 2.7
Published Sep 10, 2024
Tracked Since Feb 18, 2026