CVE-2022-31007

MEDIUM

eLabFTW <4.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-31007. PoCs published by gregscharf.

AI-analyzed exploit summary This repository contains two Python scripts that automate brute-force attacks against elabFTW's login and username enumeration vulnerabilities (CVE-2022-31007). The scripts bypass account lockout mechanisms by exploiting flawed authentication logic in versions before 4.1.0.

Description

eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.

Exploits (1)

nomisec WORKING POC 2 stars
by gregscharf · poc
https://github.com/gregscharf/CVE-2022-31007-Python-POC

This repository contains two Python scripts that automate brute-force attacks against elabFTW's login and username enumeration vulnerabilities (CVE-2022-31007). The scripts bypass account lockout mechanisms by exploiting flawed authentication logic in versions before 4.1.0.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: elabFTW < 4.1.0
No auth needed
Prerequisites: valid domain for username enumeration · wordlist for brute-forcing
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/elabftw/elabftw/releases/tag/4.3.0

Scores

CVSS v3 4.9
EPSS 0.2555
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-842 CWE-1287
Status published
Products (1)
elabftw/elabftw < 4.3.0
Published May 31, 2022
Tracked Since Feb 18, 2026