Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-15219 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator. |
Fixes
Solution
C4G BLIS users should update to version 3.51 or later.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T22:41:06.846Z
Reserved: 2019-01-07T00:00:00
Link: CVE-2019-5644
No data.
Status : Modified
Published: 2019-11-06T19:15:12.547
Modified: 2024-11-21T04:45:17.750
Link: CVE-2019-5644
No data.
OpenCVE Enrichment
No data.
EUVD