VYPR

LabCollector

by LabCollector

CVEs (2)

  • CVE-2023-33253HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.03

    LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as…

  • CVE-2019-25438Feb 20, 2026
    risk 0.00cvss epss 0.00

    LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the…