VulnerabilityModified
CVE-2021-32698
This vulnerability allows an attacker to make GET requests on behalf of the server.
MEDIUM 4.9EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- elabftw/elabftw
- Source
- security-advisories@github.com
References
- https://github.com/elabftw/elabftw/commit/3d2db4d3ad90b0915f29f05aeba41eaaf6a7c726Patch, Third Party Advisory
- https://github.com/elabftw/elabftw/security/advisories/GHSA-mh6g-62p8-26m4Patch, Third Party Advisory
- https://github.com/elabftw/elabftw/commit/3d2db4d3ad90b0915f29f05aeba41eaaf6a7c726Patch, Third Party Advisory
- https://github.com/elabftw/elabftw/security/advisories/GHSA-mh6g-62p8-26m4Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.