SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32698

This vulnerability allows an attacker to make GET requests on behalf of the server.

MEDIUM 4.9EPSS 0.94%

Does this matter?

Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.

Description

eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.

CVSS 3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
0.94% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
elabftw/elabftw
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.