CVE-2014-2659

Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
papercutpapercut_mf
𝑥
≤ 14.1
papercutpapercut_mf
12.0
papercutpapercut_mf
12.1
papercutpapercut_mf
12.2
papercutpapercut_mf
12.3
papercutpapercut_mf
12.4
papercutpapercut_mf
12.5
papercutpapercut_mf
13.0
papercutpapercut_mf
13.1
papercutpapercut_mf
13.2
papercutpapercut_mf
13.3
papercutpapercut_mf
13.4
papercutpapercut_mf
13.5
papercutpapercut_mf
14.0
papercutpapercut_ng
𝑥
≤ 14.1
papercutpapercut_ng
12.0
papercutpapercut_ng
12.1
papercutpapercut_ng
12.2
papercutpapercut_ng
12.3
papercutpapercut_ng
12.4
papercutpapercut_ng
12.5
papercutpapercut_ng
13.0
papercutpapercut_ng
13.1
papercutpapercut_ng
13.2
papercutpapercut_ng
13.3
papercutpapercut_ng
13.4
papercutpapercut_ng
13.5
papercutpapercut_ng
14.0
𝑥
= Vulnerable software versions