PT-2021-23964 · Elabftw · Elabftw
Anargam
+1
·
Published
2021-12-15
·
Updated
2021-12-21
·
CVE-2021-43833
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
eLabFTW versions prior to 4.2.0
Description:
The issue allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address, impacting instances without an explicit email domain name allowlist. Administrators and targeted users are not notified of account changes. An attacker needs to control an account to exploit this. The default settings require administrators to validate newly created accounts.
Recommendations:
For versions prior to 4.2.0, upgrade to at least version 4.2.0 to resolve the issue.
For users unable to upgrade, enable an email domain allow list from the Sysconfig panel, Security tab, to completely resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elabftw