Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-25206

Опубликовано: 14 фев. 2025
Источник: nvd
CVSS3: 8.3
CVSS3: 8.8
EPSS Низкий

Описание

eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookies are enabled (default setting). Users must upgrade to eLabFTW version 5.1.15 to receive a fix. No known workarounds are available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*
Версия до 5.1.15 (исключая)

EPSS

Процентиль: 68%
0.00585
Низкий

8.3 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89

EPSS

Процентиль: 68%
0.00585
Низкий

8.3 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89