Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-25632

8.6 · HIGH
Published Oct 1, 2024 elabftw CWE-266 EPSS 0.40% (33th pctl)

Overview

CVE-2024-25632 is a high-severity vulnerability affecting elabftw elabftw. It was published on October 1, 2024 and has a CVSS 3.1 base score of 8.6 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.6, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required.

Remediation

Check the references section for vendor advisories and patches from elabftw. Update elabftw to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
elabftw elabftw >= 4.6.0, < 5.1.0 Affected

Frequently Asked Questions

What is CVE-2024-25632?

CVE-2024-25632 is a high-severity vulnerability affecting elabftw elabftw. It was published on October 1, 2024 and has a CVSS 3.1 base score of 8.6 (HIGH).

How severe is CVE-2024-25632?

This vulnerability has a CVSS 3.1 base score of 8.6, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-25632?

Check the references section for vendor advisories and patches from elabftw. Update elabftw to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-25632?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-25632 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.