Elabftw

Elabftw

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 01.06.2026 22:24:18
  • Zuletzt bearbeitet 03.06.2026 17:06:52

eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that include resources the requesting user is not authorized to view. The expo...

  • EPSS 0.25%
  • Veröffentlicht 05.05.2026 13:16:28
  • Zuletzt bearbeitet 12.05.2026 13:58:22

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary...

  • EPSS 0.24%
  • Veröffentlicht 27.10.2025 21:25:45
  • Zuletzt bearbeitet 15.04.2026 00:35:42

eLabFTW is an open source electronic lab notebook for research labs. The application served uploaded SVG files inline. Because SVG supports active content, an attacker could upload a crafted SVG that executes script when viewed, resulting in stored X...

  • EPSS 0.45%
  • Veröffentlicht 14.02.2025 17:15:19
  • Zuletzt bearbeitet 18.08.2025 18:23:58

eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database...

  • EPSS 0.21%
  • Veröffentlicht 09.12.2024 19:15:13
  • Zuletzt bearbeitet 15.08.2025 18:43:27

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An att...

  • EPSS 0.27%
  • Veröffentlicht 14.10.2024 18:15:04
  • Zuletzt bearbeitet 08.11.2024 15:41:00

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "search.php". ...

  • EPSS 0.39%
  • Veröffentlicht 01.10.2024 15:15:08
  • Zuletzt bearbeitet 14.02.2025 16:47:37

eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is allowed (some...

  • EPSS 0.39%
  • Veröffentlicht 01.10.2024 15:15:07
  • Zuletzt bearbeitet 15.08.2025 14:07:27

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one...

  • EPSS 0.32%
  • Veröffentlicht 02.09.2024 18:15:22
  • Zuletzt bearbeitet 16.09.2024 17:28:07

eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a visitor's browser runs arbitrary JavaScript code in the context of the eLabFTW application. Th...

  • EPSS 0.24%
  • Veröffentlicht 15.08.2024 19:15:18
  • Zuletzt bearbeitet 19.08.2025 15:17:10

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accounts. A vulnerability has been found starting in version 4.4.0 and prior to version 5.0.0 that allows r...