Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-31007-Python-POC — elabFTW < 4.1.0 - account lockout bypass and login brute force | Kitploit
Tools/GitHubGitHub/gregscharf/cve-2022-31007-python-poc
Password AttacksVulnerability AnalysisExploitationWeb SecurityPenetration TestingAuthentication
GitHubgregscharf/cve-2022-31007-python-poc

CVE-2022-31007-Python-POC

elabFTW < 4.1.0 - account lockout bypass and login brute force

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
23 years agoNot yet reviewed

Python automation of the following write up on an elabFTW account lockout bypass and login brute force that affects versions before 4.1.0.

Both scripts can be used against Proving Grounds Practice lab named Source, which is running a vulnerable version of elabFTW - a free and open source electronic lab notebook.

The account login requires an email address so a valid domain of any potential user needs to be known before brute forcing user names.

Once a valid account is found put that into the login brute force script.

Download Tool