CVE-2024-1222

HIGH

PaperCut NG/MF - Privilege Escalation

Title source: llm
STIX 2.1

Description

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

Scores

CVSS v3 8.6
EPSS 0.0223
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-250
Status published
Products (2)
papercut/papercut_mf < 20.1.10
papercut/papercut_ng < 20.1.10
Published Mar 14, 2024
Tracked Since Feb 18, 2026