Executive brief
A vulnerability in Print Shop Pro WebDesk, a software suite used to manage print shop operations and web-to-print services, allows unauthorized users to grant themselves administrative privileges. By manipulating a specific setting during account registration or profile updates, an attacker can gain full control over the application. This could lead to the exposure of sensitive customer data, disruption of printing services, and unauthorized access to management functions.
Technical details
A privilege escalation vulnerability exists in edu Business Solutions Print Shop Pro WebDesk v.18.34 due to improper privilege management (CWE-269) and a lack of server-side validation on the 'AccessID' parameter. An attacker can self-register an account and then submit a crafted profile update request to the '/PSP/app/web/reg/reg_process.asp' endpoint, setting the 'AccessID' parameter to '1'. Because the application trusts this client-supplied value without verifying the user's current authorization level, the attacker's account is promoted to Super Admin status. This allows for full application takeover and access to administrative functionality at '/PSP/appNet/ManagerHome.aspx'. The issue is resolved in version 19.76.
Affected products
- edu Business Solutions Print Shop Pro WebDesk 18.34 (fixed in 19.76)
Timeline
- 2026-02-20: disclosed: Initial disclosure and CVE assignment
- 2026-02-20: advisory: NVD publication date
- 2026-05-14: patched: Updated description confirms fix in version 19.76