Vulnerabilities
Vulnerable Software
Myq-Solution:  Security Vulnerabilities
MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.
CVSS Score
9.8
EPSS Score
0.011
Published
2024-01-23
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct URL.
CVSS Score
8.8
EPSS Score
0.008
Published
2023-04-26
MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require authorization. An attacker can inject arbitrary OS commands (such as commands to create new .php files) via the Task Scheduler component.
CVSS Score
8.8
EPSS Score
0.041
Published
2021-06-21


Contact Us

Shodan ® - All rights reserved