Executive brief
LORIS, a web-based platform used by research institutions to manage neuroimaging data and projects, contains a security flaw in its imaging browser component. An attacker could exploit this to view or modify sensitive research data stored in the system's database. This could lead to the unauthorized exposure of medical research information or the corruption of project records.
Technical details
A SQL injection vulnerability exists in the MRI feedback popup window of the LORIS imaging browser. The flaw is caused by improper neutralization of user-supplied input before it is used in SQL queries (CWE-89). A remote, unauthenticated attacker can exploit this over the network with low complexity to execute arbitrary SQL commands. This allows for the unauthorized retrieval of sensitive database information or the modification of existing records. The issue is resolved in versions 27.0.3 and 28.0.1.
Affected products
- aces Loris < 27.0.3, >= 28.0.0, < 28.0.1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched