CVE-2024-1884: Server Side Request Forgery in PaperCut NG/MF
This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1884?
CVE-2024-1884 is classified as a high severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2024-1884?
To fix CVE-2024-1884, update PaperCut NG/MF to the latest version available, ensuring it is beyond the specified vulnerable versions.
What versions of PaperCut are affected by CVE-2024-1884?
CVE-2024-1884 affects various versions of PaperCut NG/MF including those below 20.1.10 and between the ranges of 21.0.0 to 21.2.14, 22.0.0 to 22.1.5, and 23.0.1 to 23.0.7.
What type of vulnerability is CVE-2024-1884?
CVE-2024-1884 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
Can CVE-2024-1884 be exploited remotely?
Yes, CVE-2024-1884 can be exploited remotely, allowing attackers to induce the server-side application to make HTTP requests to arbitrary domains.