Fresenius Kabi Vigilant Software Suite (Mastermed...
Critical severity
Unreviewed
Published
Jan 22, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Jan 21, 2022
Published to the GitHub Advisory Database
Jan 22, 2022
Last updated
Jan 28, 2023
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.
References