CVE-2024-1882

This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
PaperCutCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
papercutpapercut_mf
𝑥
< 20.1.10
papercutpapercut_mf
21.0.0 ≤
𝑥
< 21.2.14
papercutpapercut_mf
22.0.0 ≤
𝑥
< 22.1.5
papercutpapercut_mf
23.0.1 ≤
𝑥
< 23.0.7
papercutpapercut_ng
𝑥
< 20.1.10
papercutpapercut_ng
21.0.0 ≤
𝑥
< 21.2.14
papercutpapercut_ng
22.0.0 ≤
𝑥
< 22.1.5
papercutpapercut_ng
23.0.1 ≤
𝑥
< 23.0.7
𝑥
= Vulnerable software versions