Описание
eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.0 (исключая)
cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00261
Низкий
6.8 Medium
CVSS3
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-918
EPSS
Процентиль: 49%
0.00261
Низкий
6.8 Medium
CVSS3
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-918