CVE-2023-27107

Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct URL.
References
Link Resource
https://gist.github.com/smidtbx10/f8ff1c4977b7f54886c6a52e9ef4e816 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myq-solution:central_server:*:*:*:*:*:*:*:*
cpe:2.3:a:myq-solution:central_server:8.2:-:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:*:*:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:-:*:*:*:*:*:*

History

No history.

Information

Published : 2023-04-26 22:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-27107

Mitre link : CVE-2023-27107

CVE.ORG link : CVE-2023-27107


JSON object : View

Products Affected

myq-solution

  • central_server
  • print_server
CWE
CWE-863

Incorrect Authorization