Vulnerabilities > Papercut > Papercut NG > 20.1.10

DATE CVE VULNERABILITY TITLE RISK
2024-12-10 CVE-2024-9672 Cross-site Scripting vulnerability in Papercut MF
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF.
network
low complexity
papercut CWE-79
5.4
2024-09-26 CVE-2024-8404 Link Following vulnerability in Papercut NG
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled.
local
low complexity
papercut CWE-59
7.8
2024-05-14 CVE-2024-4712 Unspecified vulnerability in Papercut MF
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided.
local
low complexity
papercut
7.8
2024-05-14 CVE-2024-3037 Files or Directories Accessible to External Parties vulnerability in Papercut MF
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled.
local
low complexity
papercut CWE-552
7.8
2024-05-03 CVE-2023-39469 Code Injection vulnerability in Papercut MF
PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability.
network
low complexity
papercut CWE-94
7.2
2023-08-04 CVE-2023-39143 Path Traversal vulnerability in Papercut MF
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.
network
low complexity
papercut CWE-22
critical
9.8