Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-15218 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation. |
Fixes
Solution
C4G BLIS users should update to version 3.51 or later.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T19:14:34.337Z
Reserved: 2019-01-07T00:00:00
Link: CVE-2019-5643
No data.
Status : Modified
Published: 2019-11-06T19:15:12.453
Modified: 2024-11-21T04:45:17.640
Link: CVE-2019-5643
No data.
OpenCVE Enrichment
No data.
EUVD