Web Stack: A security weakness
Web Stack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
- Component
- Web Stack
- Plugin slug
web-stack- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Feb 02, 2022
This CVE was published Feb 02, 2022 and is one of 8 known issues for this plugin.
Update, patch or deactivate.
Update Web Stack to a release outside the affected range, or disable and remove it until a fixed version is available.
No confirmed safe version is listed. Consider a vendor-supported patch or temporarily restricting the affected functionality while you assess the risk.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.
NVD vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Primary and upstream sources
- NVD record for CVE-2021-42642
- Upstream reference printerlogic.com
- Upstream reference portswigger.net
- Upstream reference securityaffairs.co
- Upstream reference thecyberthrone.in
- Upstream reference printerlogic.com
- Upstream reference securityweek.com
- Upstream reference yahooinc.com
- Upstream reference printerlogic.com
- Upstream reference portswigger.net
- Upstream reference securityaffairs.co
- Upstream reference thecyberthrone.in
- Upstream reference printerlogic.com
- Upstream reference securityweek.com
- Upstream reference yahooinc.com