nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-1882 CVE-2024-1882
HIGH
Server-side resource injection in PaperCut NG/MF
Record summary
CVE-2024-1882 has a selected CVSS score of 7.2 (high).
Description
This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 16, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
PaperCut NG, PaperCut MFBrowse PaperCut / PaperCut NG, PaperCut MFDefault status: affected | CVE List | Before 23.0.7 | affected |
| Before 22.1.5 | affected | ||
| Before 21.2.14 | affected | ||
| Before 20.1.10 | affected | ||
papercut_mfBrowse papercut / papercut_mfDefault status: affected | CVE List | Before 23.0.7 | affected |
| Before 22.1.5 | affected | ||
| Before 21.2.14 | affected | ||
| Before 20.1.10 | affected | ||
papercut_ngBrowse papercut / papercut_ngDefault status: affected | CVE List | Before 23.0.7 | affected |
| Before 22.1.5 | affected | ||
| Before 21.2.14 | affected | ||
| Before 20.1.10 | affected |
References
2papercut.com
https://www.papercut.com/kb/Main/Security-Bulletin-March-2024