CVE-2021-32698

MEDIUM

eLabFTW <4.0.0 - SSRF

Title source: llm
STIX 2.1

Description

eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0032
EPSS Percentile 55.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
elabftw/elabftw < 4.0.0
Published Jun 21, 2021
Tracked Since Feb 18, 2026