CVE-2019-25438Disclosure(agilebio / labcollector)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database information without authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • labcollector

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
labcollector

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVETodo@CveTodo
    Disclosure

    CVE-2019-25438 pertains to multiple SQL injection vulnerabilities present in LabCollector version 5.423. These vulnerabilities allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious payloads through specific POST parameters, notably `login` in `login.php` and `user_name` in `retrieve_password.php`. The exploitation of these vulnerabilities can lead to unauthorized access to sensitive database information, including user data, configuration details, and potentially other critical data stored within the application's database. #Cybersecurity #CVE #HighSeverity #SecurityAlert #SQLInjection #PrivilegeEscalation https://cvetodo.com/cve/CVE-2019-25438

    Post summary

    The post announces CVE-2019-25438, exposing SQL injection weaknesses in LabCollector 5.423 that let unauthenticated attackers run arbitrary SQL commands via specific POST parameters, potentially revealing sensitive data.

    0000028
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25438 LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code … https://www.cve.org/CVERecord?id=CVE-2019-25438

    Post summary

    The text announces CVE-2019-25438 as a set of SQL injection flaws in LabCollector 5.423, detailing the vulnerability type without providing proof of exploitation or mitigations.

    0000048
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagilebiolabcollector5.423--

Explore more