CVE-2024-9672: Reflected XSS in PaperCut MF
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9672?
CVE-2024-9672 has been classified as a reflected cross-site scripting (XSS) vulnerability, which can be exploited to execute arbitrary JavaScript in a user's browser.
How do I fix CVE-2024-9672?
To fix CVE-2024-9672, it is recommended to update PaperCut NG/MF to version 24.1.1 or later.
What are the affected versions for CVE-2024-9672?
CVE-2024-9672 affects PaperCut NG and PaperCut MF versions up to 24.1.1.
What could attackers do with CVE-2024-9672?
Attackers can leverage CVE-2024-9672 to execute harmful JavaScript code in the context of a user's session, potentially stealing information or performing actions on their behalf.
Who needs to be concerned about CVE-2024-9672?
Organizations using PaperCut NG or PaperCut MF should be concerned about CVE-2024-9672 due to the potential for exploitation through user interaction with malicious links.