Executive brief
GisLab Laboratory Management System is a web application used to manage laboratory operations and resources. A path traversal vulnerability allows an attacker to access files outside the intended directory structure, potentially exposing sensitive data such as configuration files, credentials, or other confidential information stored on the server.
Technical details
This vulnerability is a classic path traversal (CWE-22) in GisLab Laboratory Management System versions 1.4.03 through 1.4.x before version 1.5. The vulnerability allows attackers to use special path sequences (e.g., "../" or absolute paths) to navigate the file system and access restricted files. The attack is likely network-accessible without authentication requirements, making it readily exploitable. An attacker can read arbitrary files accessible by the application process, potentially obtaining sensitive system information or application secrets. A patch is available in version 1.5 and later.
Affected products
- GIS Informatics GisLab Laboratory Management System 1.4.03 to before 1.5
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fix available in version 1.5 and later