Vulnerability Description
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Myq-Solution | Central Server | < 8.2 |
| Myq-Solution | Print Server | < 8.2 |
Related Weaknesses (CWE)
References
- https://gist.github.com/smidtbx10/f8ff1c4977b7f54886c6a52e9ef4e816ExploitThird Party Advisory
- https://gist.github.com/smidtbx10/f8ff1c4977b7f54886c6a52e9ef4e816ExploitThird Party Advisory
FAQ
What is CVE-2023-27107?
CVE-2023-27107 is a vulnerability with a CVSS score of 8.8 (HIGH). Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to gen...
How severe is CVE-2023-27107?
CVE-2023-27107 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27107?
Check the references section above for vendor advisories and patch information. Affected products include: Myq-Solution Central Server, Myq-Solution Print Server.