PT-2024-17486 · Papercut · Papercut Ng/Mf

Published

2024-03-14

·

Updated

2024-09-26

·

CVE-2024-1221

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PaperCut NG/MF (affected versions not specified)
Description This issue potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This issue only affects Linux and macOS PaperCut NG/MF servers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-1221
ZDI-24-780

Affected Products

Papercut Ng/Mf