Elabftw

Elabftw

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 16.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:53

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. This vulnerab...

  • EPSS 0.32%
  • Veröffentlicht 16.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:53

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 22.10.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:39

eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header....

  • EPSS 0.32%
  • Veröffentlicht 21.06.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:33

eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched i...

Exploit
  • EPSS 26.43%
  • Veröffentlicht 20.05.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:23

eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This w...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 03.01.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:49

ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.