Vulnerabilities > Papercut > Papercut NG

DATE CVE VULNERABILITY TITLE RISK
2024-03-14 CVE-2024-1221 Unspecified vulnerability in Papercut MF
This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint.
network
high complexity
papercut
3.1
2024-03-14 CVE-2024-1222 Unspecified vulnerability in Papercut MF
This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges.
network
low complexity
papercut
critical
9.8
2024-03-14 CVE-2024-1223 Unspecified vulnerability in Papercut MF
This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs.
network
high complexity
papercut
4.8
2024-03-14 CVE-2024-1654 Unspecified vulnerability in Papercut MF
This vulnerability potentially allows unauthorized write operations which may lead to remote code execution.
network
low complexity
papercut
7.2
2023-11-14 CVE-2023-6006 Unspecified vulnerability in Papercut MF
This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG.
local
low complexity
papercut
6.7
2023-10-19 CVE-2023-31046 Path Traversal vulnerability in Papercut MF
A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1.
network
low complexity
papercut CWE-22
6.5
2023-09-13 CVE-2023-4568 Improper Authentication vulnerability in Papercut NG
PaperCut NG allows for unauthenticated XMLRPC commands to be run by default.
network
low complexity
papercut CWE-287
6.5
2023-08-04 CVE-2023-39143 Path Traversal vulnerability in Papercut MF
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.
network
low complexity
papercut CWE-22
critical
9.8
2023-07-25 CVE-2023-3486 Unrestricted Upload of File with Dangerous Type vulnerability in Papercut MF
An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage.
network
low complexity
papercut CWE-434
7.5
2023-06-20 CVE-2023-2533 Cross-Site Request Forgery (CSRF) vulnerability in Papercut MF and Papercut NG
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
network
low complexity
papercut CWE-352
8.8