Impact
The vulnerability is an SQL injection flaw in GisLab Laboratory Management System that allows an attacker to inject arbitrary SQL into backend queries. The flaw enables unauthorized read or modification of the database.
Affected Systems
Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. produces the GisLab Laboratory Management System. Versions affected are 1.4.03 through 08072026.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score of less than 1% suggests a low but nonzero exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The CVE description does not specify the attack vector or authentication requirements, so those details remain unknown.
OpenCVE Enrichment