Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-8297: GisLab Laboratory Management System SQL Injection Vulnerability
CVE-2026-8297
CVE-2026-8297
Summary
The GisLab Laboratory Management System is vulnerable to SQL injection attacks, which could allow unauthorized access to sensitive data. This affects versions 1.4.03 and later, up to 08072026. Users should update to a fixed version of the software to ensure security.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gis informatics engineering consulting laboratory r&d and software services inc. | gislab laboratory management system | <= 08072026 |
Original title
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laborat...
Original description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection.
This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
mitre CVSS3.1
9.8
Vulnerability type
CWE-89
SQL Injection
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0573 government-resource
Published: 17 Jul 2026 · Updated: 18 Jul 2026 · First seen: 17 Jul 2026