Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-8297: GisLab Laboratory Management System SQL Injection Vulnerability

CVE-2026-8297 CVE-2026-8297
Summary

The GisLab Laboratory Management System is vulnerable to SQL injection attacks, which could allow unauthorized access to sensitive data. This affects versions 1.4.03 and later, up to 08072026. Users should update to a fixed version of the software to ensure security.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gis informatics engineering consulting laboratory r&d and software services inc. gislab laboratory management system <= 08072026
Original title
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laborat...
Original description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection.

This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
mitre CVSS3.1 9.8
Vulnerability type
CWE-89 SQL Injection
Published: 17 Jul 2026 · Updated: 18 Jul 2026 · First seen: 17 Jul 2026