Printerlogic Web Stack 19.1.1.13 Service Pack 2

CPE Details

Printerlogic Web Stack 19.1.1.13 Service Pack 2
19.1.1.13
2022-02-02
17h34 +00:00
2022-02-07
16h23 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp2:*:*:*:*:*:*

Informations

Vendor

printerlogic

Product

web_stack

Version

19.1.1.13

Update

sp2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-42642 2022-02-02 16h23 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.
7.5
Haute
CVE-2021-42641 2022-02-02 16h21 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
7.5
Haute
CVE-2021-42640 2022-02-02 16h18 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
9.1
Critique
CVE-2021-42639 2022-02-02 16h16 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.
6.1
Moyen
CVE-2021-42637 2022-02-02 16h14 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
9.8
Critique
CVE-2021-42633 2022-02-02 16h10 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
5.3
Moyen
CVE-2021-42638 2022-02-01 21h08 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
8.1
Haute
CVE-2021-42635 2022-01-31 16h54 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
8.1
Haute
CVE-2021-42631 2022-01-31 16h48 +00:00 PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
8.1
Haute