CVE-2024-22076

MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myq-solution:print_server:*:*:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:-:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:beta1:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch1:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch10:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch11:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch12:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch13:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch14:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch15:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch16:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch17:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch18:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch19:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch2:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch20:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch21:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch22:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch23:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch24:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch25:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch26:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch27:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch28:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch29:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch3:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch30:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch31:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch32:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch33:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch34:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch35:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch36:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch37:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch38:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch39:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch4:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch40:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch41:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch42:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch5:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch6:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch7:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch8:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch9:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:rc1:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:rc2:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:rc3:*:*:*:*:*:*

History

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://docs.myq-solution.com/en/print-server/8.2/ - Release Notes () https://docs.myq-solution.com/en/print-server/8.2/ - Release Notes
References () https://docs.myq-solution.com/en/print-server/8.2/technical-changelog#id-%288.2%29ReleaseNotes-8.2%28Patch43%29 - Release Notes () https://docs.myq-solution.com/en/print-server/8.2/technical-changelog#id-%288.2%29ReleaseNotes-8.2%28Patch43%29 - Release Notes
References () https://www.access42.nl/nieuws/unmasking-web-vulnerabilities-a-tale-of-default-admin-credentials-and-php-command-execution-cve-2024-22076/ - () https://www.access42.nl/nieuws/unmasking-web-vulnerabilities-a-tale-of-default-admin-credentials-and-php-command-execution-cve-2024-22076/ -

22 Feb 2024, 02:15

Type Values Removed Values Added
Summary MyQ Print Server before 8.2 patch 43 allows Unauthenticated Remote Code Execution. MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.

16 Feb 2024, 09:15

Type Values Removed Values Added
References
  • () https://www.access42.nl/nieuws/unmasking-web-vulnerabilities-a-tale-of-default-admin-credentials-and-php-command-execution-cve-2024-22076/ -

30 Jan 2024, 16:30

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://docs.myq-solution.com/en/print-server/8.2/ - () https://docs.myq-solution.com/en/print-server/8.2/ - Release Notes
References () https://docs.myq-solution.com/en/print-server/8.2/technical-changelog#id-%288.2%29ReleaseNotes-8.2%28Patch43%29 - () https://docs.myq-solution.com/en/print-server/8.2/technical-changelog#id-%288.2%29ReleaseNotes-8.2%28Patch43%29 - Release Notes
First Time Myq-solution
Myq-solution print Server
CPE cpe:2.3:a:myq-solution:print_server:8.2:patch9:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch4:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:beta1:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch5:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch14:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:rc1:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch25:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch40:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch10:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch6:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch26:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:-:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch23:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch29:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch22:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch18:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch38:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch20:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch1:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch35:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch24:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:*:*:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch16:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch21:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch39:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch32:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:rc3:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch13:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch36:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch37:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch12:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch2:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch11:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch19:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch34:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch41:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch8:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch15:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch3:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch42:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch7:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch28:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:rc2:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch17:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch30:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch33:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch27:*:*:*:*:*:*
cpe:2.3:a:myq-solution:print_server:8.2:patch31:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

23 Jan 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-23 11:15

Updated : 2024-11-21 08:55


NVD link : CVE-2024-22076

Mitre link : CVE-2024-22076

CVE.ORG link : CVE-2024-22076


JSON object : View

Products Affected

myq-solution

  • print_server