Vasion Print Arbitrary Content Inclusion Vulnerability via Iframe
Vulnerability
An arbitrary content inclusion vulnerability has been identified in Vasion Print (formerly PrinterLogic) versions prior to Virtual Appliance Host 22.0.843 and Application 20.0.1923. This vulnerability allows for the inclusion of arbitrary content through iframes, potentially leading to the execution of JavaScript or the initiation of file downloads from untrusted sources. The issue could be exploited by deceiving a user into clicking a malicious link and executing the downloaded content.
Impact
Exploitation of this vulnerability could allow for arbitrary content to be included and executed, potentially leading to the execution of malicious scripts or the download of harmful files.
Remediation
Users can update to Vasion Print, Virtual Appliance Host 22.0.843 / Application 20.0.1923 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
