CVE-2024-1883: medium-severity vulnerability in PaperCut NG, PaperCut MF
Reflected XSS in PaperCut NG/MF
Published · Updated
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 61%
exploitation probability
61%top 1% of all CVEs
observed exploitation
nono source reports it
This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Affected products
PaperCut · PaperCut NG, PaperCut MFRelated CVEs — PaperCut NG, PaperCut MF
In the same product, most dangerous first.
CVE-2024-1222HIGHIncorrect authorization controls in PaperCut NG/MF APIsEPSS 64.0%CVE-2024-1884MEDIUMServer Side Request Forgery in PaperCut NG/MFEPSS 37.9%CVE-2024-1882HIGHServer-side resource injection in PaperCut NG/MFEPSS 1.4%CVE-2024-1654HIGHUnauthorized write operations in PaperCut NG/MFEPSS 1.3%CVE-2024-1221LOWImproper access controls on APIs on Linux and macOS in PaperCut NG/MFEPSS 0.5%CVE-2024-1223MEDIUMImproper authorization controls in PaperCut NG/MFEPSS 0.4%