Vulnerabilities > Papercut > Papercut NG
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-12-10 | CVE-2024-9672 | Cross-site Scripting vulnerability in Papercut MF A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. | 5.4 |
2024-11-22 | CVE-2023-39470 | Unspecified vulnerability in Papercut NG PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. | 7.2 |
2024-09-26 | CVE-2024-8404 | Link Following vulnerability in Papercut NG An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. | 7.8 |
2024-09-26 | CVE-2024-8405 | Command Injection vulnerability in Papercut NG An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. | 5.5 |
2024-05-14 | CVE-2024-4712 | Unspecified vulnerability in Papercut MF An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. | 7.8 |
2024-05-14 | CVE-2024-3037 | Files or Directories Accessible to External Parties vulnerability in Papercut MF An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. | 7.8 |
2024-05-03 | CVE-2023-39469 | Code Injection vulnerability in Papercut MF PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. | 7.2 |
2024-03-14 | CVE-2024-1882 | Unspecified vulnerability in Papercut MF This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server. | 7.2 |
2024-03-14 | CVE-2024-1883 | Cross-site Scripting vulnerability in Papercut MF This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. | 6.1 |
2024-03-14 | CVE-2024-1884 | Server-Side Request Forgery (SSRF) vulnerability in Papercut MF This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. | 6.5 |