CVE-2024-25632

HIGH

eLabFTW <5.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required.

References (1)

Core 1
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://github.com/elabftw/elabftw/security/advisories/GHSA-6m7p-gh9f-5mgg

Scores

CVSS v3 8.6
EPSS 0.0039
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-842
Status published
Products (1)
elabftw/elabftw 4.6.0 - 5.1.0
Published Oct 01, 2024
Tracked Since Feb 18, 2026