MEDIUM
eLabFTW HTML / CSS Injection via Malicious SVG Upload Leads to Credential Theft / Clickjacking
Published Oct 27, 2025
6.8
MEDIUMCVSS 3.1
EPSS 0.26%
Description
eLabFTW is an open source electronic lab notebook for research labs. The application served uploaded SVG files inline. Because SVG supports active content, an attacker could upload a crafted SVG that executes script when viewed, resulting in stored XSS under the application origin. A victim who opens the SVG URL or any page embedding it could have their session hijacked, data exfiltrated, or actions performed on their behalf. This vulnerability is fixed n 5.3.0.
Affected products
-
- Version < 5.3.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36380 Advisory
- https://github.com/elabftw/elabftw/commit/09b95e38f82f041edac0dd6962c70499e2d8d8e2 x_refsource_MISC
- https://github.com/elabftw/elabftw/security/advisories/GHSA-rq98-8jh9-684f x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36380 | Advisory | |
| https://github.com/elabftw/elabftw/commit/09b95e38f82f041edac0dd6962c70499e2d8d8e2 | x_refsource_MISC | |
| https://github.com/elabftw/elabftw/security/advisories/GHSA-rq98-8jh9-684f | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 27, 2025
Updated Oct 28, 2025
Reserved Oct 22, 2025
Link CVE-2025-62793
CISA Vulnrichment
Updated Oct 28, 2025
ENISA EUVD
EUVD-2025-36380 Assigner GitHub_M
Published Oct 27, 2025
Updated Oct 28, 2025
Exploited since n/a
Link EUVD-2025-36380