Reflected Cross Site Scripting Vulnerability in PaperCut NG/MF Application Server
CVE-2024-1883

6.1MEDIUM

Key Information:

Vendor
Papercut
Vendor
CVE Published:
14 March 2024

Summary

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

Affected Version(s)

PaperCut NG, PaperCut MF MacOS 0

PaperCut NG, PaperCut MF MacOS 0 < 23.0.7

PaperCut NG, PaperCut MF MacOS 0 < 22.1.5

References

EPSS Score

32% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.