Impact
A path traversal flaw in GIS Informatics' GisLab Laboratory Management System means that an attacker can supply a specially crafted path to the web application, causing the system to read files outside the intended directory. This can lead to disclosure of confidential files such as configuration, credentials, or system logs, and in certain setups could be leveraged to execute code by including and evaluating files.
Affected Systems
GIS Informatics, GisLab Laboratory Management System, versions from 1.4.03 through any release prior to 1.5.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is not published, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a crafted request parameter that bypasses directory restrictions, which an external attacker could supply if the web interface is reachable from the internet.
OpenCVE Enrichment