Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-15192 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user. |
Fixes
Solution
C4G BLIS users should update to version 3.5 or later.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-17T02:21:04.696Z
Reserved: 2019-01-07T00:00:00
Link: CVE-2019-5617
No data.
Status : Modified
Published: 2019-11-06T19:15:12.233
Modified: 2024-11-21T04:45:14.853
Link: CVE-2019-5617
No data.
OpenCVE Enrichment
No data.
EUVD