CVE-2024-45408
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 1, 2024
Updated: Feb 28, 2025
CWE ID 284
Summary
CVE-2024-45408 is a vulnerability affecting eLabFTW, an open-source electronic lab notebook. This issue involves an incorrect permission check that allows authenticated users to access restricted information. If anonymous access is enabled, this vulnerability can be exploited by anyone. Users are urged to upgrade to version 5.1.0 or higher to mitigate this risk. System administrators can also disable anonymous access through the System configuration panel as an additional security measure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.