Vulnerabilities (CVE)

Filtered by vendor Printeron Subscribe
Filtered by product Central Print Services
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17213 1 Printeron 1 Central Print Services 2024-02-04 4.0 MEDIUM 8.8 HIGH
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.
CVE-2018-17210 1 Printeron 1 Central Print Services 2024-02-04 6.5 MEDIUM 8.8 HIGH
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks (that would otherwise logout a low-privileged user) by calling the core print job components directly via crafted HTTP GET and POST requests.
CVE-2018-17211 1 Printeron 1 Central Print Services 2024-02-04 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.