Printerlogic Web Stack 19.1.1.13 Service Pack 2

CPE Details

Printerlogic Web Stack 19.1.1.13 Service Pack 2
19.1.1.13
2022-02-02
17h34 +00:00
2022-02-07
16h23 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp2:*:*:*:*:*:*

Informations

Vendor

printerlogic

Product

web_stack

Version

19.1.1.13

Update

sp2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-42642 2022-02-02 16h23 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.
7.5
High
CVE-2021-42641 2022-02-02 16h21 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
7.5
High
CVE-2021-42640 2022-02-02 16h18 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
9.1
Critical
CVE-2021-42639 2022-02-02 16h16 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.
6.1
Medium
CVE-2021-42637 2022-02-02 16h14 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
9.8
Critical
CVE-2021-42633 2022-02-02 16h10 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
5.3
Medium
CVE-2021-42638 2022-02-01 21h08 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
8.1
High
CVE-2021-42635 2022-01-31 16h54 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
8.1
High
CVE-2021-42631 2022-01-31 16h48 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
8.1
High