Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Moderate
C4G BLIS Improper Access Control
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.
0
Attacker Value
Unknown
CVE-2022-32429
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
0
Attacker Value
Unknown
CVE-2021-32685
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.
0
Attacker Value
Unknown
CVE-2019-5643
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation.
0
Attacker Value
Unknown
CVE-2019-5617
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user.
0