CVE-2024-1882: high-severity vulnerability in PaperCut NG, PaperCut MF
Server-side resource injection in PaperCut NG/MF
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 1.4%
exploitation probability
1.4%top 28% of all CVEs
observed exploitation
nono source reports it
This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
PaperCut · PaperCut NG, PaperCut MFRelated CVEs — PaperCut NG, PaperCut MF
In the same product, most dangerous first.
CVE-2024-1222HIGHIncorrect authorization controls in PaperCut NG/MF APIsEPSS 64.0%CVE-2024-1883MEDIUMReflected XSS in PaperCut NG/MFEPSS 61.5%CVE-2024-1884MEDIUMServer Side Request Forgery in PaperCut NG/MFEPSS 37.9%CVE-2024-1654HIGHUnauthorized write operations in PaperCut NG/MFEPSS 1.3%CVE-2024-1221LOWImproper access controls on APIs on Linux and macOS in PaperCut NG/MFEPSS 0.5%CVE-2024-1223MEDIUMImproper authorization controls in PaperCut NG/MFEPSS 0.4%