RSS   Vulnerabilities for 'Central print services'   RSS

2019-07-29
 
CVE-2018-17213

CWE-287
 

 
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.

 
 
CVE-2018-17211

CWE-200
 

 
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.

 
2019-07-19
 
CVE-2018-17210

CWE-285
 

 
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks (that would otherwise logout a low-privileged user) by calling the core print job components directly via crafted HTTP GET and POST requests.

 

 >>> Vendor: Printeron 2 Products
Printeron
Central print services


Copyright 2024, cxsecurity.com

 

Back to Top