ZeroHour

CVE-2023-27107

PoC
CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct URL.

Vendors
myq-solution
Products
central server, print server
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.