Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22950 | eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 15 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:* |
Tue, 01 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required. | |
| Title | Unauthorised granting of administrator privileges over arbitrary teams under certain circumstances | |
| Weaknesses | CWE-266 CWE-842 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-01T15:00:01.610Z
Reserved: 2024-02-08T22:26:33.512Z
Link: CVE-2024-25632
Updated: 2024-10-01T14:59:57.676Z
Status : Analyzed
Published: 2024-10-01T15:15:07.383
Modified: 2025-08-15T14:07:27.313
Link: CVE-2024-25632
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:25Z
EUVD