ZeroHour

CVE-2026-9163

niche

Unauthenticated SQL Injection in GIS Informatics GisLab Laboratory Management System

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-9163 is a critical SQL injection flaw (CWE-89) in the GIS Informatics GisLab Laboratory Management System, caused by improper neutralization of special elements used in SQL commands. Per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can trigger it over the network by sending crafted input that is incorporated into database queries, with no privileges or user interaction required. Successful exploitation could let the attacker read, modify, or delete data in the system's database, potentially exposing sensitive laboratory records and disrupting the application, as reflected by the high confidentiality, integrity, and availability impacts. Organizations running GisLab Laboratory Management System versions 1.4.03 up to, but not including, 1.5 are affected. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the vulnerability is not listed in CISA's KEV catalog.

What to do: Upgrade GisLab Laboratory Management System to version 1.5 or later, as the affected range ends before 1.5. Until upgraded, restrict network access to the application to trusted lab networks, since the flaw is exploitable remotely without credentials, and review database/application logs for unusual queries or unexpected data access. Monitor vendor and USOM advisories for updated guidance, and note there is no public proof-of-concept to validate against yet.

Affected
GIS Informatics GisLab Laboratory Management Systemall versions from 1.4.03 up to (but not including) 1.5
Estimated exposure
nichelikely no more than hundreds of laboratory installations (estimate; no public install-base data available) — GisLab is a specialized laboratory management system from a small vendor whose advisory was assigned by Turkey's USOM, with no public install counts or internet-exposure scan data, so deployments are presumed limited to a small number of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.