Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Benjamin Schmidt

Pesquisador deSpike Reply GmbH
#29157de 53,633
8.8CVSS total
Vulnerabilidades · 1
PT-2023-20957
8.8
2023-04-26
Unknown · Myq Solution Print Server · CVE-2023-27107
**Name of the Vulnerable Software and Affected Versions** MyQ Solution Print Server versions prior to 8.2 Patch 32 MyQ Solution Central Server versions prior to 8.2 Patch 22 **Description** The issue is related to incorrect access control in the `runReport` function, allowing users without appropriate access rights to generate internal reports using a direct URL. **Recommendations** For MyQ Solution Print Server versions prior to 8.2 Patch 32, update to version 8.2 Patch 32 or later. For MyQ Solution Central Server versions prior to 8.2 Patch 22, update to version 8.2 Patch 22 or later. As a temporary workaround, consider restricting access to the `runReport` function until a patch is available.