"product_name":"Basic Laboratory Information System",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_value":"3.5"
}
]
}
}
]
},
"vendor_name":"Computing For Good"
}
]
}
},
"credit":[
{
"lang":"eng",
"value":"This vulnerability was first discovered privately and reported internally by C4G BLIS team member Aditi Shah in December 2018. Jacob Robles of Rapid7 rediscovered and reported these issues in March of 2019 per Rapid7's vulnerability disclosure policy (https://www.rapid7.com/security/disclosure/)."
"value":"Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, \"Improper Access Control.\" As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator."