U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-28100

Change History

New CVE Received from GitHub, Inc. 9/02/2024 2:15:22 PM

Action Type Old Value New Value
Added Description

								
							
							
						
eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a visitor's browser runs arbitrary JavaScript code in the context of the eLabFTW application. This can be triggered by the visitor viewing a list of experiments. Viewing this allows the malicious script to act on behalf of the visitor in any way, including the creation of API keys for persistence, or other options normally available to the user. If the user viewing the page has the sysadmin role in eLabFTW, the script can act as a sysadmin (including system configuration and extensive user management roles). Users are advised to upgrade to at least version 5.0.0. There are no known workarounds for this vulnerability.
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Added CWE

								
							
							
						
GitHub, Inc. CWE-79
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/elabftw/elabftw/security/advisories/GHSA-xp3v-w8cx-cqxc [No types assigned]