First published: Tue Apr 22 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PaperCut NG | <=14.1 | |
PaperCut NG | =12.0 | |
PaperCut NG | =12.1 | |
PaperCut NG | =12.2 | |
PaperCut NG | =12.3 | |
PaperCut NG | =12.4 | |
PaperCut NG | =12.5 | |
PaperCut NG | =13.0 | |
PaperCut NG | =13.1 | |
PaperCut NG | =13.2 | |
PaperCut NG | =13.3 | |
PaperCut NG | =13.4 | |
PaperCut NG | =13.5 | |
PaperCut NG | =14.0 | |
PaperCut NG | <=14.1 | |
PaperCut NG | =12.0 | |
PaperCut NG | =12.1 | |
PaperCut NG | =12.2 | |
PaperCut NG | =12.3 | |
PaperCut NG | =12.4 | |
PaperCut NG | =12.5 | |
PaperCut NG | =13.0 | |
PaperCut NG | =13.1 | |
PaperCut NG | =13.2 | |
PaperCut NG | =13.3 | |
PaperCut NG | =13.4 | |
PaperCut NG | =13.5 | |
PaperCut NG | =14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2659 is a high-severity cross-site request forgery vulnerability impacting the admin user interface of PaperCut MF and NG versions prior to 14.1.
To fix CVE-2014-2659, upgrade to PaperCut MF or NG version 14.1 or later.
CVE-2014-2659 affects PaperCut MF and NG versions 12.0 to 14.0.
CVE-2014-2659 allows attackers to perform unauthorized actions through the admin UI by exploiting CSRF vulnerabilities.
CVE-2014-2659 can lead to unauthorized actions being performed on behalf of administrators, potentially compromising the security of the PaperCut application.