NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-25632
Summary

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required.

Publication Date Oct. 2, 2024, 12:15 a.m.
Registration Date Oct. 2, 2024, noon
Last Update Oct. 4, 2024, 10:51 p.m.
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
eLabFTW における不適切な権限設定に関する脆弱性
Title eLabFTW における不適切な権限設定に関する脆弱性
Summary

eLabFTW には、不適切な権限設定に関する脆弱性、誤ったグループへのユーザの配置に関する脆弱性が存在します。

Possible impacts 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダアドバイザリまたはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。

Publication Date Oct. 1, 2024, midnight
Registration Date Aug. 19, 2025, 5:47 p.m.
Last Update Aug. 19, 2025, 5:47 p.m.
Affected System
eLabFTW
eLabFTW 4.6.0 以上 5.1.0 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
その他
Change Log
No Changed Details Date of change
1 [2025年08月19日]   掲載 Aug. 19, 2025, 3:30 p.m.