VYPR

Papercut Ng

by Papercut

CVEs (29)

  • CVE-2023-27350CriKEVApr 20, 2023
    risk 0.93cvss 9.8epss 1.00

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…

  • CVE-2023-27351HigKEVApr 20, 2023
    risk 0.73cvss 7.5epss 0.77

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results…

  • CVE-2023-39143CriAug 4, 2023
    risk 0.70cvss 9.8epss 0.80

    PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

  • CVE-2023-2533HigKEVJun 20, 2023
    risk 0.69cvss 8.4epss 0.29

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current…

  • CVE-2019-12135CriJun 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.

  • CVE-2019-8948CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.04

    PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.

  • CVE-2024-1222HigMar 14, 2024
    risk 0.61cvss 8.6epss 0.64

    This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

  • CVE-2023-3486HigJul 25, 2023
    risk 0.59cvss 8.2epss 0.79

    An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as…

  • CVE-2026-6180HigMay 5, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence…

  • CVE-2024-8404HigSep 26, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2024-4712HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is…

  • CVE-2024-3037HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2023-39469HigMay 3, 2024
    risk 0.51cvss 7.2epss 0.58

    PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2023-6006HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system.…

  • CVE-2023-39470HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The…

  • CVE-2024-1882HigMar 14, 2024
    risk 0.47cvss 7.2epss 0.01

    This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.

  • CVE-2024-1654HigMar 14, 2024
    risk 0.47cvss 7.2epss 0.01

    This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.

  • CVE-2024-1883MedMar 14, 2024
    risk 0.46cvss 6.3epss 0.61

    This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to…

  • CVE-2024-1884MedMar 14, 2024
    risk 0.45cvss 6.5epss 0.38

    This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.

  • CVE-2023-4568MedSep 13, 2023
    risk 0.43cvss 6.5epss 0.04

    PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

Page 1 of 2