vendor:
PrinterOn Enterprise
by:
bzyo
6.5
CVSS
MEDIUM
Arbitrary File Deletion
20
CWE
Product Name: PrinterOn Enterprise
Affected Version From: 4.1.4
Affected Version To: 4.1.4
Patch Exists: NO
Related CWE: CVE-2018-19936
CPE: a:printeron:printeron_enterprise:4.1.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 2012 R2 Datacenter
2018
PrinterOn Enterprise 4.1.4 – Arbitrary File Deletion
When either printing as a Guest (when enabled) or as an Authenticated user via the CPS URL https://<hostname or ip>/cps, the user printing has the ability to delete any file on the host system that isn’t currently in use by the system itself. The field to enter a web page does not properly check the URI being entered, as such the user can enter a system file path and delete a file on the system.
Mitigation:
Ensure that the CPS URL is properly configured to only allow access to authenticated users and that the URI field is properly checked for malicious input.