Fiche vulnérabilité
CVE-2023-27107 : faille élevée myq-solution central server (CVSS 8.8)
Description
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct URL.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 avr. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- myq-solution central server
- myq-solution print server