Agilebio Labcollector vulnerabilities
2 known vulnerabilities affecting agilebio/labcollector.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2023-33253P2HIGHCVSS 8.8≥ 6.0, ≤ 6.152023-06-12
CVE-2023-33253 [HIGH] CWE-434 CVE-2023-33253: LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged us
LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.
nvd
CVE-2019-25438P3HIGHCVSS 7.5v5.4232026-02-20
CVE-2019-25438 [HIGH] CWE-89 CVE-2019-25438: LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attack
LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database inf
nvd