Vulnary
← back to the feed
Critical· 9.8

CVE-2026-8297

A critical SQL injection vulnerability exists in GisLab Laboratory Management System versions 1.4.03 through 08072026. An attacker can send specially crafted input to execute arbitrary SQL commands, potentially leading to full compromise of confidentiality, integrity, and availability. The vulnerability has a CVSS base score of 9.8.

publishedJul 17, 2026
last modifiedJul 17, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
18th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of GisLab Laboratory Management System versions 1.4.03 through 08072026.

02

Real-world impact

Successful exploitation could allow an attacker to read, modify, or delete database data, and potentially take control of the affected system.

03

Why this severity

The CVSS v3.1 base score of 9.8 (Critical) reflects that the vulnerability is exploitable over the network, requires low attack complexity, needs no privileges or user interaction, and results in high impacts to confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is mentioned in the provided sources. Users should monitor the vendor’s advisories for future patches and consider applying input validation or using parameterized queries as a temporary mitigation.
interim mitigations
  • Apply strict input validation and use parameterized queries or prepared statements to prevent SQL injection.

Remediation steps are based on general secure coding practices because no vendor patch is referenced in the data.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →