PT-2024-21052 · Elabftw · Elabftw
Anargam
·
Published
2024-10-01
·
Updated
2025-08-15
·
CVE-2024-25632
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
eLabFTW versions prior to 5.1.0
Description
The issue allows a regular user to become an administrator of a team where they are a member, under a reasonable configuration. In versions subsequent to v5.0.0, it may also allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. This does not affect system administrator status.
Recommendations
For versions prior to 5.1.0, users should upgrade to version 5.1.0.
System administrators are advised to turn off local user registration, saml team create, and not allow administrators to import users into teams, unless strictly required.
Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elabftw