#VU127371 SQL injection in eLabFTW - CVE-2025-25206
Published: February 14, 2025 / Updated: April 24, 2026
eLabFTW
elabftw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in database query handling when processing user-supplied input. A remote user can send crafted input to disclose sensitive information.
If cookies are enabled, exploitation could lead to privilege escalation.