ZDI-CAN-23074: ZDI-24-780: PaperCut NG upload Link Following Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PaperCut NG. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-1221.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23074?
The severity of ZDI-CAN-23074 is rated at 6.5 according to the CVSS scoring system.
How do I fix ZDI-CAN-23074?
To fix ZDI-CAN-23074, ensure that you update your PaperCut NG installation to the latest patched version provided by the vendor.
What type of attack does ZDI-CAN-23074 enable?
ZDI-CAN-23074 allows remote attackers to disclose sensitive information by bypassing the existing authentication mechanism.
Is authentication required to exploit ZDI-CAN-23074?
Yes, although authentication is required, it can be bypassed due to the vulnerability.
Which software is affected by ZDI-CAN-23074?
The affected software for ZDI-CAN-23074 is PaperCut NG.