CVE-2026-9163: SQLi in GIS Informatics' GisLab Laboratory Management System
Published Sep 10, 2026
·Updated
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection.
This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.
Affected Software
1 affected component
GIS Informatics GisLab Laboratory Management System>1.4.03<=1.5
Event History
Sep 10, 2026
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
GisLab Laboratory Management System versions from 1.4.03 up to, but not including, 1.5 are affected.
2
Does exploitation require authentication or user interaction?
No. The provided vector indicates network-reachable exploitation with low attack complexity, requiring neither privileges nor user interaction.
3
What could a successful attack allow?
The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability.