Search

Find a vulnerability

Search criteria

    6 vulnerabilities found for papercut_mf by papercut

    CVE-2024-8404 (GCVE-0-2024-8404)

    Vulnerability from cvelistv5 – Published: 2024-09-26 01:42 – Updated: 2025-05-13 01:39
    VLAI
    Title
    Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder
    Summary
    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. Important: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server. Update: This CVE has been updated in May 2025 to update the fixed version and fix process. Please refer to the May 2025 Security Bulletin. Note: This CVE has been split from CVE-2024-3037.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-26 14:59 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    Impacted products
    Vendor Product Version
    PaperCut PaperCut NG, PaperCut MF Affected: 0 , < 24.1.7 (custom)
    Create a notification for this product.
    papercut papercut_mf Affected: 0 , < 23.0.9 (custom)
        cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    papercut papercut_ng Affected: 0 , < 23.0.9 (custom)
        cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-26 01:35
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "papercut_mf",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "papercut_ng",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8404",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-26T14:59:11.788417Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-26T15:01:21.951Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Web Print"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "PaperCut NG, PaperCut MF",
              "vendor": "PaperCut",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "24.1.7",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "24.1.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Amol Dosanjh of Trend Micro"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Nicholas Zubrisky (@NZubrisky) of Trend Micro"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Michael DePlante (@izobashi) of Trend Micro\u0027s ZDI"
            }
          ],
          "datePublic": "2024-09-26T01:35:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eAn arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eUpdate:\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eThis CVE has been updated in May 2025 to update the fixed version and fix process. Please refer to the May 2025 Security Bulletin.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eNote: \u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eThis CVE has been split from CVE-2024-3037.\u003c/span\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nUpdate:\n\nThis CVE has been updated in May 2025 to update the fixed version and fix process. Please refer to the May 2025 Security Bulletin.\n\nNote: \n\nThis CVE has been split from CVE-2024-3037."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-165",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-165 File Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-13T01:39:33.742Z",
            "orgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "shortName": "PaperCut"
          },
          "references": [
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-May-2025/"
            },
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
        "assignerShortName": "PaperCut",
        "cveId": "CVE-2024-8404",
        "datePublished": "2024-09-26T01:42:49.400Z",
        "dateReserved": "2024-09-04T05:55:44.460Z",
        "dateUpdated": "2025-05-13T01:39:33.742Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3037 (GCVE-0-2024-3037)

    Vulnerability from cvelistv5 – Published: 2024-05-14 00:12 – Updated: 2024-10-07 20:27
    VLAI
    Title
    Arbitrary File Deletion in PaperCut NG/MF Web Print
    Summary
    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server. Important: In most installations, this risk is mitigated by the default Windows Server configuration, which typically restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log in to the local console of the Windows environment hosting the PaperCut NG/MF application server. Note: This CVE has been split into two separate CVEs (CVE-2024-3037 and CVE-2024-8404) and it’s been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard users on the host server.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-07 20:25 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    Impacted products
    Vendor Product Version
    PaperCut PaperCut NG, PaperCut MF Affected: 0 , < 23.0.9 (custom)
    Create a notification for this product.
    papercut papercut_ng Affected: 0 , < 23.0.9 (custom)
        cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
    Create a notification for this product.
    papercut papercut_mf Affected: 0 , < 23.0.9 (custom)
        cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:32:42.646Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.papercut.com/kb/Main/security-bulletin-may-2024/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "papercut_ng",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "papercut_mf",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3037",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-07T20:25:16.955265Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-07T20:27:00.841Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Web Print"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "PaperCut NG, PaperCut MF",
              "vendor": "PaperCut",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "23.0.9",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "23.0.9",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Nicholas Zubrisky (@NZubrisky)"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Michael DePlante(@izobashi) of Trend Micro\u0027s ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eAn arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server. \u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which typically restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log in to the local console of the Windows environment hosting the PaperCut NG/MF application server.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: transparent;\"\u003eNote: This CVE has been split into two separate CVEs (CVE-2024-3037 and CVE-2024-8404) and it\u2019s been rescored with a \"Privileges Required (PR)\" rating of low, and \u201cAttack Complexity (AC)\u201d rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard users on the host server.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which typically restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log in to the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nNote: This CVE has been split into two separate CVEs (CVE-2024-3037 and CVE-2024-8404) and it\u2019s been rescored with a \"Privileges Required (PR)\" rating of low, and \u201cAttack Complexity (AC)\u201d rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard users on the host server."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-165",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-165 File Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-26T01:15:01.885Z",
            "orgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "shortName": "PaperCut"
          },
          "references": [
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Arbitrary File Deletion in PaperCut NG/MF Web Print",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
        "assignerShortName": "PaperCut",
        "cveId": "CVE-2024-3037",
        "datePublished": "2024-05-14T00:12:37.696Z",
        "dateReserved": "2024-03-28T04:33:02.602Z",
        "dateUpdated": "2024-10-07T20:27:00.841Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1884 (GCVE-0-2024-1884)

    Vulnerability from cvelistv5 – Published: 2024-03-14 03:11 – Updated: 2024-08-28 15:12
    VLAI
    Title
    Server Side Request Forgery in PaperCut NG/MF
    Summary
    This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-14 15:43 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    PaperCut PaperCut NG, PaperCut MF Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
    Create a notification for this product.
    papercut papercut_ng Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
    Create a notification for this product.
    papercut papercut_mf Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:56:22.318Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_ng",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_mf",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1884",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-14T15:43:10.845115Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T15:12:02.085Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "MacOS",
                "Linux",
                "Windows"
              ],
              "product": "PaperCut NG, PaperCut MF",
              "vendor": "PaperCut",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "23.0.7",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "23.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "22.1.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "22.1.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "21.2.14",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "21.2.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "20.1.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "20.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that  allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker\u0027s choosing."
                }
              ],
              "value": "This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that  allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker\u0027s choosing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-664",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-664 Server-Side Request Forgery (SSRF)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-14T03:11:48.197Z",
            "orgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "shortName": "PaperCut"
          },
          "references": [
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Server Side Request Forgery in PaperCut NG/MF",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
        "assignerShortName": "PaperCut",
        "cveId": "CVE-2024-1884",
        "datePublished": "2024-03-14T03:11:48.197Z",
        "dateReserved": "2024-02-26T05:36:24.198Z",
        "dateUpdated": "2024-08-28T15:12:02.085Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1882 (GCVE-0-2024-1882)

    Vulnerability from cvelistv5 – Published: 2024-03-14 03:08 – Updated: 2024-09-26 03:52
    VLAI
    Title
    Server-side resource injection in PaperCut NG/MF
    Summary
    This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-16 04:00 UTC
    CWE
    • CWE-76 - Improper Neutralization of Equivalent Special Elements
    Impacted products
    Vendor Product Version
    PaperCut PaperCut NG, PaperCut MF Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
    Create a notification for this product.
    papercut papercut_ng Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
    Create a notification for this product.
    papercut papercut_mf Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_ng",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_mf",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1882",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-16T04:00:55.398174Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T16:02:52.603Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:56:22.441Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "MacOS",
                "Linux",
                "Windows"
              ],
              "product": "PaperCut NG, PaperCut MF",
              "vendor": "PaperCut",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "23.0.7",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "23.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "22.1.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "22.1.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "21.2.14",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "21.2.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "20.1.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "20.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.\u003cbr\u003e"
                }
              ],
              "value": "This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-253",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-253 Remote Code Inclusion"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-76",
                  "description": "CWE-76 Improper Neutralization of Equivalent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-26T03:52:57.154Z",
            "orgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "shortName": "PaperCut"
          },
          "references": [
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Server-side resource injection in PaperCut NG/MF",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
        "assignerShortName": "PaperCut",
        "cveId": "CVE-2024-1882",
        "datePublished": "2024-03-14T03:08:17.914Z",
        "dateReserved": "2024-02-26T05:36:21.950Z",
        "dateUpdated": "2024-09-26T03:52:57.154Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1654 (GCVE-0-2024-1654)

    Vulnerability from cvelistv5 – Published: 2024-03-14 03:06 – Updated: 2024-08-01 18:48
    VLAI
    Title
    Unauthorized write operations in PaperCut NG/MF
    Summary
    This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-16 04:00 UTC
    CWE
    • CWE-183 - Permissive List of Allowed Inputs
    Impacted products
    Vendor Product Version
    PaperCut PaperCut NG, PaperCut MF Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
    Create a notification for this product.
    papercut papercut_mf Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    papercut papercut_ng Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_mf",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_ng",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1654",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-16T04:00:54.272578Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T16:04:21.347Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:48:21.853Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "MacOS",
                "Linux",
                "Windows"
              ],
              "product": "PaperCut NG, PaperCut MF",
              "vendor": "PaperCut",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "23.0.7",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "23.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "22.1.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "22.1.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "21.2.14",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "21.2.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "20.1.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "20.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this. "
                }
              ],
              "value": "This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this. "
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-253",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-253 Remote Code Inclusion"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-183",
                  "description": "CWE-183 Permissive List of Allowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-14T03:06:54.867Z",
            "orgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "shortName": "PaperCut"
          },
          "references": [
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Unauthorized write operations in PaperCut NG/MF",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
        "assignerShortName": "PaperCut",
        "cveId": "CVE-2024-1654",
        "datePublished": "2024-03-14T03:06:54.867Z",
        "dateReserved": "2024-02-20T02:23:09.252Z",
        "dateUpdated": "2024-08-01T18:48:21.853Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1222 (GCVE-0-2024-1222)

    Vulnerability from cvelistv5 – Published: 2024-03-14 03:03 – Updated: 2024-09-26 03:50
    VLAI
    Title
    Incorrect authorization controls in PaperCut NG/MF APIs
    Summary
    This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-26 04:00 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    PaperCut PaperCut NG, PaperCut MF Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
    Create a notification for this product.
    papercut papercut_mf Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    papercut papercut_ng Affected: 0 , < 23.0.7 (custom)
    Affected: 0 , < 22.1.5 (custom)
    Affected: 0 , < 21.2.14 (custom)
    Affected: 0 , < 20.1.10 (custom)
        cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:33:25.592Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_mf",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "papercut_ng",
                "vendor": "papercut",
                "versions": [
                  {
                    "lessThan": "23.0.7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2.14",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.1.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1222",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-26T04:00:45.176980Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T15:10:56.143Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "MacOS",
                "Linux",
                "Windows"
              ],
              "product": "PaperCut NG, PaperCut MF",
              "vendor": "PaperCut",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "23.0.7",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "23.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "22.1.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "22.1.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "21.2.14",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "21.2.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "20.1.10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "20.1.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250: Execution with Unnecessary Privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-26T03:50:54.624Z",
            "orgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
            "shortName": "PaperCut"
          },
          "references": [
            {
              "url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Incorrect authorization controls in PaperCut NG/MF APIs",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
        "assignerShortName": "PaperCut",
        "cveId": "CVE-2024-1222",
        "datePublished": "2024-03-14T03:03:18.638Z",
        "dateReserved": "2024-02-05T04:34:00.207Z",
        "dateUpdated": "2024-09-26T03:50:54.624Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }