Elabftw

Elabftw

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 01.08.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:03

eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are advised to up...

  • EPSS 26.1%
  • Veröffentlicht 31.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:42

eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or cr...

  • EPSS 0.98%
  • Veröffentlicht 16.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:53

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option ...

  • EPSS 0.81%
  • Veröffentlicht 16.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:53

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. This vulnerab...

Exploit
  • EPSS 1.88%
  • Veröffentlicht 22.10.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:39

eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header....

  • EPSS 0.94%
  • Veröffentlicht 21.06.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:33

eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched i...

Exploit
  • EPSS 18.11%
  • Veröffentlicht 20.05.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:23

eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This w...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 03.01.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:49

ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.