VYPR
High severity7.5NVD Advisory· Published Oct 1, 2024· Updated Jun 17, 2026

CVE-2024-45408

CVE-2024-45408

Description

eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is allowed (something disabled by default), this extends to anyone. Users are advised to upgrade to at least version 5.1.0. System administrators can disable anonymous access in the System configuration panel.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Elabftw/Elabftw3 versions
    cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*range: >=4.4.0,<5.1.0
    • (no CPE)range: >=5.1.0
    • (no CPE)range: >= 4.4.0, < 5.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.