Impact
The vulnerability enables an attacker to override authorization checks by presenting a user‑controlled key or trusted identifier, turning a legitimate IDOR into an unchecked access path. read or modify laboratory records that belong to other users, potentially exposing confidential health information or corrupting test results. The weakness lies in improper handling of sensitive identifiers (CWE‑639).
Affected Systems
GisLab Laboratory Management System, versions 1.4.03 through 08072026, distributed by Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity, and the EPSS score of less than 1 % suggests that real‑world exploitation is unlikely. The system is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, via the web interface, where an authenticated user can supply a stolen or guessed identifier to retrieve or modify records belonging to another. Successful exploitation requires knowledge of a valid identifier and may also rely on the absence of request validation or role‑based access controls.
OpenCVE Enrichment