PT-2021-23964 · Elabftw · Elabftw

Anargam

+1

·

Published

2021-12-15

·

Updated

2021-12-21

·

CVE-2021-43833

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: eLabFTW versions prior to 4.2.0
Description: The issue allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address, impacting instances without an explicit email domain name allowlist. Administrators and targeted users are not notified of account changes. An attacker needs to control an account to exploit this. The default settings require administrators to validate newly created accounts.
Recommendations: For versions prior to 4.2.0, upgrade to at least version 4.2.0 to resolve the issue. For users unable to upgrade, enable an email domain allow list from the Sysconfig panel, Security tab, to completely resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43833
GHSA-V659-Q2FH-V99W

Affected Products

Elabftw