Vasion Print Password Exposure Vulnerability via URL
Vulnerability
A vulnerability exists in Vasion Print (formerly PrinterLogic) versions prior to Virtual Appliance Host 22.0.843 and Application 20.0.1923, allowing passwords to be transmitted through query parameters in the URL. This could lead to unintentional exposure of sensitive information via referrer headers, browser history, server logs, and other channels that may decode the URL back to plain text.
Impact
This vulnerability could result in passwords being leaked to third parties through various logging and referral mechanisms, potentially allowing unauthorized access to user accounts.
Remediation
Users can update to Vasion Print, Virtual Appliance Host 22.0.843 / Application 20.0.1923 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
