Описание
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
Ссылки
- Product
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Product
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 19.1.1.13 (исключая)
Одно из
cpe:2.3:a:printerlogic:web_stack:*:*:*:*:*:*:*:*
cpe:2.3:a:printerlogic:web_stack:19.1.1.13:-:*:*:*:*:*:*
cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp2:*:*:*:*:*:*
cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp3-3:*:*:*:*:*:*
cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp9:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00796
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668
Связанные уязвимости
github
почти 4 года назад
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
EPSS
Процентиль: 74%
0.00796
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668