CVE-2025-25206 – eLabFTW Privilege Escalation Information Disclosure

The following table lists the changes that have been made to the
CVE-2025-25206 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 14, 2025

    Action Type Old Value New Value
    Added Description eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookies are enabled (default setting). Users must upgrade to eLabFTW version 5.1.15 to receive a fix. No known workarounds are available.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
    Added CWE CWE-89
    Added Reference https://github.com/elabftw/elabftw/releases/tag/5.1.15
    Added Reference https://github.com/elabftw/elabftw/security/advisories/GHSA-qffc-rfjh-77gg
Share the Post:

Related Posts