eLabFTW 4.3.0 Beta 5

CPE Details

eLabFTW 4.3.0 Beta 5
4.3.0
2022-08-05
14h24 +00:00
2022-08-05
14h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:elabftw:elabftw:4.3.0:beta5:*:*:*:*:*:*

Informations

Vendor

elabftw

Product

elabftw

Version

4.3.0

Update

beta5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-47826 2024-10-14 17h59 +00:00 eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "search.php". It works by providing HTML code in the extended search string, which will then be displayed back to the user in the error message. This means that injected HTML will appear in a red "alert/danger" box, and be part of an error message. Due to some other security measures, it is not possible to execute arbitrary javascript from this attack. As such, this attack is deemed low impact. Users should upgrade to at least version 5.1.5 to receive a patch. No known workarounds are available.
6.1
Medium
CVE-2024-28100 2024-09-02 16h10 +00:00 eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a visitor's browser runs arbitrary JavaScript code in the context of the eLabFTW application. This can be triggered by the visitor viewing a list of experiments. Viewing this allows the malicious script to act on behalf of the visitor in any way, including the creation of API keys for persistence, or other options normally available to the user. If the user viewing the page has the sysadmin role in eLabFTW, the script can act as a sysadmin (including system configuration and extensive user management roles). Users are advised to upgrade to at least version 5.0.0. There are no known workarounds for this vulnerability.
8.9
High
CVE-2022-31178 2022-08-01 19h10 +00:00 eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are advised to upgrade. There are no known workarounds for this issue.
4.3
Medium