ZDI-24-781: PaperCut NG generateNextFileName Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-1654.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-781?
The severity of ZDI-24-781 is rated at 7.2 according to the CVSS scoring system.
How do I fix ZDI-24-781?
To fix ZDI-24-781, it is recommended to apply the latest security patch provided by PaperCut for PaperCut NG.
Who can exploit ZDI-24-781?
ZDI-24-781 requires authentication, meaning that only users with valid credentials can exploit this vulnerability.
What kind of vulnerability is ZDI-24-781?
ZDI-24-781 is a remote code execution vulnerability that allows attackers to execute arbitrary code on affected installations of PaperCut NG.
Which software is affected by ZDI-24-781?
ZDI-24-781 affects installations of PaperCut NG.