PatchSiren

C4G CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH C4G CVE published 2026-04-05

CVE-2019-25678

CVE-2019-25678 is a SQL injection vulnerability in C4G Basic Laboratory Information System 3.4. Attackers can inject malicious SQL code through the site parameter in the users_select.php endpoint to extract sensitive database information. This vulnerability has a high CVSS score of 8.8, indicating a high severity level. Organizations using C4G Basic Laboratory Information System 3.4 should prioritize patc [truncated]