📦 Elabftw

by Elabftw

🔍 What is Elabftw?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-43834

CRITICAL CVSS 9.1 Dec 16, 2021

This vulnerability allows attackers to authenticate as existing users in eLabFTW instances configured with LDAP or SAML single sign-on authentication. It affects eLabFTW versions before 4.2.0 where LD...

CVE-2025-25206

HIGH CVSS 8.3 Feb 14, 2025

This SQL injection vulnerability in eLabFTW allows authenticated users to read sensitive database information, potentially including login tokens. This could lead to privilege escalation and unauthori...

CVE-2024-45408

HIGH CVSS 7.5 Oct 1, 2024

CVE-2024-45408 is an incorrect permission check vulnerability in eLabFTW that allows authenticated users to access restricted information. If anonymous access is enabled (disabled by default), unauthe...

CVE-2024-25632

HIGH CVSS 8.6 Oct 1, 2024

This vulnerability in eLabFTW allows regular users to escalate privileges to administrator within teams where they are members. In versions after v5.0.0, it may also allow unauthenticated users to gai...

CVE-2024-28100

HIGH CVSS 8.9 Sep 2, 2024

CVE-2024-28100 is a cross-site scripting (XSS) vulnerability in eLabFTW that allows authenticated users to upload malicious files that execute JavaScript in visitors' browsers. This enables attackers ...

CVE-2021-43833

HIGH CVSS 8.1 Dec 16, 2021

This vulnerability allows any authenticated user in eLabFTW to gain access to arbitrary accounts by setting a specially crafted email address. It affects all eLabFTW instances prior to version 4.2.0 t...