Back

MEDIUM

C4G BLIS Improper Access Control

Published Nov 6, 2019

Description

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation.

Affected products

Remediation

Vendor solution

C4G BLIS users should update to version 3.51 or later.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Nov 6, 2019
Updated Sep 16, 2024
Reserved Jan 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a