ZDI-24-785: PaperCut MF EmailRenderer Server-Side Template Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut MF. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-1882.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-785?
The severity of ZDI-24-785 is rated at 7.2 on the CVSS scale, indicating a high-level vulnerability.
How do I fix ZDI-24-785?
To fix ZDI-24-785, update to the latest version of PaperCut MF that addresses this vulnerability.
What type of attack does ZDI-24-785 enable?
ZDI-24-785 allows remote attackers to execute arbitrary code on affected installations of PaperCut MF.
Is authentication required to exploit ZDI-24-785?
Yes, authentication is required to exploit ZDI-24-785, but the existing authentication mechanism can be bypassed.
What can happen if ZDI-24-785 is exploited?
If ZDI-24-785 is exploited, attackers can execute arbitrary code, potentially compromising the affected system.