Impact
The vulnerability is an improper neutralization of special elements used in SQL commands, allowing attackers to inject arbitrary SQL statements into the application. This flaw permits unauthorized data access, modification, or deletion. It corresponds to CWE-89.
Affected Systems
GIS Informatics GisLab Laboratory Management System versions prior to 1.5, specifically from 1.4.03 up to 1.4.x, are affected. The vulnerability exists in the web application component that builds and executes SQL queries without proper sanitization. Users running these versions are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. No EPSS score is available, suggesting limited publicly reported exploitation data, but the flaw remains highly valuable for adversaries. The vulnerability is not listed in CISA KEV, yet the impact and potential for exploitation render it a high priority. Attackers can exploit this flaw remotely over the network by submitting crafted input through exposed web forms or API endpoints; no local privilege escalation or physical access is required. The flaw grants attackers direct control over database operations and potentially the underlying application logic.
OpenCVE Enrichment