eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookies are enabled (default setting). Users must upgrade to eLabFTW version 5.1.15 to receive a fix. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Feb 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookies are enabled (default setting). Users must upgrade to eLabFTW version 5.1.15 to receive a fix. No known workarounds are available. | |
Title | Incorrect input validation could allow an authenticated user to read sensitive information | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-14T17:28:44.566Z
Reserved: 2025-02-03T19:30:53.401Z
Link: CVE-2025-25206

Updated: 2025-02-14T17:27:30.508Z

Status : Received
Published: 2025-02-14T17:15:19.327
Modified: 2025-02-14T17:15:19.327
Link: CVE-2025-25206

No data.