Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfxc-95p3-jhv6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.

EPSS

Процентиль: 83%
0.01914
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-306

Связанные уязвимости

CVSS3: 10
nvd
больше 6 лет назад

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.

EPSS

Процентиль: 83%
0.01914
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-306