Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
papercut papercut mf vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-39143
PaperCut NG and PaperCut MF prior to 22.1.3 on Windows allow path traversal, enabling malicious users to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
Papercut Papercut Mf
Papercut Papercut Ng
1 Github repository
9.8
CVSSv3
CVE-2023-27350
This vulnerability allows remote malicious users to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from ...
Papercut Papercut Ng
Papercut Papercut Mf
10 Github repositories
3 Articles
9.8
CVSSv3
CVE-2019-12135
An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and previous versions and versions 19.0.3 and previous versions allows remote malicious users to execute arbitrary code via an unspecified vector.
Papercut Papercut Mf
Papercut Papercut Ng
9.8
CVSSv3
CVE-2019-8948
PaperCut MF prior to 18.3.6 and PaperCut NG prior to 18.3.6 allow script injection via the user interface, aka PC-15163.
Papercut Papercut Mf
Papercut Papercut Ng
8.8
CVSSv3
CVE-2023-2533
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an malicious user to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a cur...
Papercut Papercut Mf 22.0.10
Papercut Papercut Ng 22.0.10
7.5
CVSSv3
CVE-2023-3486
An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated malicious user to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating a...
Papercut Papercut Mf
Papercut Papercut Ng
7.5
CVSSv3
CVE-2023-27351
This vulnerability allows remote malicious users to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue result...
Papercut Papercut Ng
Papercut Papercut Mf
6.5
CVSSv3
CVE-2023-31046
A Path Traversal vulnerability exists in PaperCut NG prior to 22.1.1 and PaperCut MF prior to 22.1.1. Under specific conditions, this could potentially allow an authenticated malicious user to achieve read-only access to the server's filesystem, because requests beginning wi...
Papercut Papercut Mf
Papercut Papercut Ng
NA
CVE-2024-4712
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).
NA
CVE-2024-3037
An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »