Cross-site scripting in eLabFTW - #VU137348

 

Cross-site scripting in eLabFTW - #VU137348

Published: July 12, 2026


Vulnerability identifier: #VU137348
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary html or css into an exported ELN HTML preview.

The vulnerability exists due to cross-site scripting in comment text and upload filename handling when generating a .eln export preview file. A remote user can supply crafted comment text or an upload filename to inject arbitrary html or css into an exported ELN HTML preview.

User interaction is required to view the generated preview.


Affected software

eLabFTW

Remediation

Install security update from vendor's website.

eLabFTW - update to 5.6.0

External References

Related Security Bulletins