LabCollector 5.423 contains multiple SQL injection...
High severity
Unreviewed
Published
Feb 21, 2026
to the GitHub Advisory Database
•
Updated Feb 21, 2026
Description
Published by the National Vulnerability Database
Feb 20, 2026
Published to the GitHub Advisory Database
Feb 21, 2026
Last updated
Feb 21, 2026
LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database information without authentication.
References