PT-2026-30486 · C4G+1 · Basic Laboratory Information System+1
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
C4G Basic Laboratory Information System version 3.4
Description
Multiple SQL injection flaws allow unauthenticated attackers to execute arbitrary SQL commands. This is achieved by injecting malicious code through the
site parameter via GET requests sent to the 'users select.php' endpoint. This can lead to the extraction of sensitive database information, such as system credentials and patient records.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
site parameter in the 'users select.php' endpoint until the issue is resolved.Exploit
SQL injection
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Basic Laboratory Information System
Computing For Good'S Basic Laboratory Information System