Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2022-32427

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all affected are advised to upgrade.
Attacker Value
Unknown

CVE-2021-42642

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.
Attacker Value
Unknown

CVE-2021-42641

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
Attacker Value
Unknown

CVE-2021-42640

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
Attacker Value
Unknown

CVE-2021-42639

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.
Attacker Value
Unknown

CVE-2021-42637

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
Attacker Value
Unknown

CVE-2021-42633

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
Attacker Value
Unknown

CVE-2021-42638

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
Attacker Value
Unknown

CVE-2021-42635

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
Attacker Value
Unknown

CVE-2021-42631

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.