← back
CVE-2023-24217highCWE-98

CVE-2023-24217

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.8epss 4.5%
from disclosure to weapon31 days
Published on NVDMar 6
1st PoC+31d
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short

AgileBio Electronic Lab Notebook v4.234 allows attackers to access files on the server that shouldn't be publicly available. This vulnerability could expose sensitive data like configuration files or internal documents.

Technical detail

A local file inclusion (LFI) vulnerability in AgileBio Electronic Lab Notebook v4.234 allows an unauthenticated or low-privileged attacker to read arbitrary files from the server filesystem through improper input validation. The attack vector is typically via malicious file path parameters, potentially exposing sensitive configuration files, credentials, or application source code.

Summary generated and translated by AI from the official description.
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.