CVE-2021-42641

HIGH

PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference

Title source: llm
STIX 2.1

Description

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.

Scores

CVSS v3 7.5
EPSS 0.0206
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-668
Status published
Products (2)
printerlogic/web_stack 19.1.1.13 (4 CPE variants)
printerlogic/web_stack < 19.1.1.13
Published Feb 02, 2022
Tracked Since Feb 18, 2026