CVE-2022-42909
Summary
| CVE | CVE-2022-42909 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-03 19:15:00 UTC |
| Updated | 2023-02-10 17:34:00 UTC |
| Description | WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don´t own and print hem without authorization. In order to exploit this vulnerability, the user must have an account with wepanow.com or any of the institutions they serve, and be logged in. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wepanow | Print Away | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Contact Me - Enrique Benvenutto | CONFIRM | enrique.wtf | |
| Multiple vulnerabilities in WEPA Print Away | INCIBE-CERT | CONFIRM | www.incibe-cert.es | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Enrique Benvenutto Navarro
There are currently no legacy QID mappings associated with this CVE.