CVE-2025-10084 Overview
CVE-2025-10084 is an improper authorization vulnerability in elunez/eladmin versions up to 2.7. The flaw resides in the queryErrorLogDetail function of the SysLogController component, reachable through the /api/logs/error/1 endpoint. An authenticated low-privilege attacker can invoke the endpoint remotely to access error log details that should require higher privileges. The exploit technique has been publicly disclosed, increasing the likelihood of opportunistic abuse against exposed instances. The weakness is classified under CWE-266: Incorrect Privilege Assignment.
Critical Impact
Authenticated users can read sensitive error log entries from SysLogController without proper authorization, exposing application internals such as stack traces, request parameters, and potentially credentials logged during failures.
Affected Products
- eladmin (elunez/eladmin) versions up to and including 2.7
- SysLogController component exposing /api/logs/error/{id}
- Deployments where the eladmin REST API is reachable by low-privileged authenticated users
Discovery Timeline
- 2025-09-08 - CVE-2025-10084 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-10084
Vulnerability Analysis
The eladmin project is a Spring Boot based backend management system widely used in Chinese enterprise environments. The SysLogController exposes administrative log endpoints, including queryErrorLogDetail, which returns detailed error log records by identifier. The controller method does not enforce the same role-based restrictions applied to other administrative log operations. Any authenticated user with a valid session token can therefore issue a GET request to /api/logs/error/{id} and retrieve full error log payloads. Error logs commonly contain stack traces, method parameters, SQL statements, and internal application state useful to an attacker preparing follow-on activity.
Root Cause
The root cause is a missing authorization annotation on the queryErrorLogDetail handler in SysLogController. Sibling endpoints under /api/logs are protected by preauthorize checks that restrict access to administrative roles. The error log detail handler lacks the equivalent check, so the framework only validates that the caller is authenticated. This inconsistent enforcement matches the [CWE-266] pattern of incorrect privilege assignment.
Attack Vector
Exploitation requires network access to the eladmin API and any valid low-privileged account. The attacker authenticates through the standard /auth/login endpoint, obtains a bearer token, and issues authenticated GET requests iterating identifiers against /api/logs/error/{id}. No user interaction, elevated privileges, or unusual conditions are required. The publicly available proof-of-concept referenced in VulDB submission 644658 demonstrates the request sequence. See the VulDB entry for additional technical context.
Detection Methods for CVE-2025-10084
Indicators of Compromise
- Authenticated GET requests to /api/logs/error/ originating from non-administrative user accounts.
- Sequential or enumerated identifier access patterns against the error log endpoint suggesting scraping.
- Access to error log endpoints from source IPs that have never previously interacted with administrative resources.
Detection Strategies
- Correlate the JWT subject or user role in application logs against the endpoint accessed to flag privilege mismatches.
- Deploy a web application firewall rule that requires the caller role to match an administrative allowlist for any request path matching ^/api/logs/error/\d+$.
- Baseline expected callers of /api/logs/error/* and alert on first-seen principals accessing the route.
Monitoring Recommendations
- Forward eladmin access logs and Spring Security audit events into a centralized analytics platform for role-versus-route correlation.
- Track request volume spikes against /api/logs/error/* per authenticated user to identify enumeration attempts.
- Enable alerting on repeated 200 responses to log detail endpoints from accounts assigned only end-user roles.
How to Mitigate CVE-2025-10084
Immediate Actions Required
- Restrict network exposure of the eladmin management API so it is only reachable from trusted administrative networks.
- Audit user roles and revoke unnecessary accounts that could be used to authenticate against the vulnerable endpoint.
- Add a reverse-proxy access control rule denying non-administrative users from reaching /api/logs/error/* until an upstream patch is applied.
Patch Information
No official fixed release has been published in the enriched NVD data at the time of writing. Operators should track the elunez/eladmin repository for updates beyond version 2.7 and apply a private hotfix that adds a @PreAuthorize("@el.check('logError:list')") annotation, or equivalent role check, to the queryErrorLogDetail method in SysLogController. Reference the VulDB advisory for tracking.
Workarounds
- Apply a source patch that adds a preauthorize annotation matching the sibling queryErrorLog handler to enforce administrative role checks.
- Block or authenticate the /api/logs/error/* route at an upstream gateway using role claims extracted from the eladmin JWT.
- Disable or delete low-privilege accounts that do not require access to the management console until the fix is deployed.
# Nginx snippet to restrict error log detail endpoint to an admin IP allowlist
location ~ ^/api/logs/error/ {
allow 10.10.20.0/24; # admin subnet
deny all;
proxy_pass http://eladmin_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
