eladmin · Issues· 23 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #913
Courtesy notice for an independent Java 21 and Spring Boot 4.1.1 port
Updated Sep 1, 2026 - #912
[Security] JWT userId 未与 Redis 在线会话绑定,导致跨用户身份混淆与条件性垂直越权
Updated Aug 31, 2026 - #903
[Security] Missing authorization on Tools (Email / Alipay) and Code-Generator controllers enables vertical privilege escalation
Updated Jul 5, 2026 - #910
[Security] Broken Access Control - UserController
Updated Jul 1, 2026 - #909
[Security] Broken Access Control - LocalStorageController
Updated Jul 1, 2026 - #906
[Security] OS command injection in deploy server-reduction (`appName`)
Updated Jun 25, 2026 - #907
[Security] SSRF via attacker-controlled JDBC URL in database maintenance endpoints
Updated Jun 25, 2026 - #908
[Security] Arbitrary file write via code-generator `tableName` (path traversal)
Updated Jun 25, 2026 - #868
The version of the MySQL connector used by eladmin v2.6 is outdated, which makes it vulnerable to JDBC deserialization attacks.
Updated Jun 15, 2026 - #901
[Security]Directory Traversal in File Upload Path Construction Allows Write Outside the Intended Upload Directory
Updated Jun 4, 2026 - #904
Arbitrary file read via /api/database/testConnect: the sanitizeJdbcUrl blocklist is bypassable
Updated Jun 3, 2026 - #902
[Security]Users with low privileges can reset the password of any user.
Updated May 20, 2026 - #900
[Security] Server-Side Request Forgery (SSRF) via Insecure JDBC Connection Testing
Updated May 13, 2026 - #899
[Secruity] Command Injection via SSH Script Injection in App Management in elunez_eladmin
Updated May 13, 2026 - #892
建议修改tableName传参方式
Updated Mar 28, 2026