LORIS (Longitudinal Online Research and Imaging System) versions prior to 27.0.3 and 28.0.1 contain a SQL injection vulnerability in the MRI feedback popup window of the imaging browser module. This self-hosted neuroimaging research data management application is susceptible to unauthorized data access and modification through malicious SQL queries. The vulnerability affects the application's ability to securely handle user input in specific code sections related to imaging feedback functionality. The vulnerability carries a CVSS 3.1 severity rating of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, indicating that exploitation does not require specialized conditions or insider knowledge. The primary impact is confidentiality compromise, allowing attackers to access sensitive neuroimaging research data stored on affected servers, though data integrity and system availability are not directly impacted by this particular vulnerability. Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on relevant threat tracking lists. The EPSS score of 0.00044 indicates this vulnerability is currently exploited less frequently than the majority of public CVEs. Organizations running affected LORIS versions should apply patches 27.0.3 or 28.0.1 to remediate this risk, particularly given the sensitive nature of neuroimaging research data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 27.0.3CPE matchmatch criteria | cpe:2.3:a:mcgill:loris:*:*:*:*:*:*:*:* | ||
28.0.0CPE matchmatch criteria | cpe:2.3:a:mcgill:loris:28.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.