A critical SQL injection vulnerability exists in GisLab Laboratory Management System versions from 1.4.03 through 08072026. The issue allows attackers to inject malicious SQL code, potentially leading to unauthorized data access and manipulation. This vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. The CVE record indicates that the vulnerability is caused by improper neutralization of [truncated]
MEDIUMGis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.CVE published 2026-07-17
CVE-2026-11763 is an authorization bypass vulnerability through a user-controlled key in GisLab Laboratory Management System. The vulnerability allows exploitation of trusted identifiers and has a CVSS score of 6.5 (MEDIUM). Affected product deployments exist in managed environments, and owners should be assigned for follow-up. The CVE record was published on 2026-07-17T17:17:13.047Z and has not been modi [truncated]