PatchSiren cyber security CVE debrief
CVE-2019-25678 C4G CVE debrief
CVE-2019-25678 is a SQL injection vulnerability in C4G Basic Laboratory Information System 3.4. Attackers can inject malicious SQL code through the site parameter in the users_select.php endpoint to extract sensitive database information. This vulnerability has a high CVSS score of 8.8, indicating a high severity level. Organizations using C4G Basic Laboratory Information System 3.4 should prioritize patching this vulnerability to prevent potential data breaches.
- Vendor
- C4G
- Product
- Basic Laboratory Information System
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-05
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-05
- Advisory updated
- 2026-07-24
Who should care
Organizations using C4G Basic Laboratory Information System 3.4 should prioritize patching this vulnerability to prevent potential data breaches. The vulnerability has a high CVSS score of 8.8, indicating a high severity level. Security teams and vulnerability management teams should review the CVE record and NVD detail page for CVE-2019-25678 to understand the affected scope and severity.
Technical summary
The vulnerability allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter in the users_select.php endpoint. This can lead to the extraction of sensitive database information, including patient records and system credentials. The vulnerability has a high CVSS score of 8.8, indicating a high severity level. Organizations using C4G Basic Laboratory Information System 3.4 should prioritize patching this vulnerability to prevent potential data breaches. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Defensive priority
High priority due to the high CVSS score of 8.8 and the potential for significant data exposure.
Recommended defensive actions
- Apply patches or updates provided by the vendor to fix the SQL injection vulnerability.
- Implement input validation and sanitization for user-supplied data to prevent SQL injection attacks.
- Monitor system logs for suspicious activity and implement additional security measures to detect and respond to potential attacks.
- Conduct regular vulnerability assessments and penetration testing to identify and address potential vulnerabilities.
- Consider implementing a web application firewall (WAF) to detect and prevent SQL injection attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-04-05T21:16:45.967Z and last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Analyzed. The source item URL for CVE-2019-25678 was provided by nvd_modified. The CVE-2019-25678 CVE record is available from CVE.org. The NVD detail page for CVE-2019-25678 is available from NVD. There is an Exploit-DB entry for CVE-2019-25678. A third-party advisory for CVE-2019-25678 is also available.
Official resources
-
CVE-2019-25678 CVE record
CVE.org
-
CVE-2019-25678 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Exploit, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-05T21:16:45.967Z and has not been modified since then. The NVD entry is currently Analyzed.