ZDI-CAN-23254: ZDI-24-784: PaperCut MF handleServiceException Cross-Site Scripting Authentication Bypass Vulnerability
Published Jun 18, 2024
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut MF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-1883.
Affected Software
1 affected component
PaperCut MF
Event History
Jun 18, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23254?
The severity of ZDI-CAN-23254 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-CAN-23254?
To fix ZDI-CAN-23254, update your PaperCut MF installation to the latest patched version provided by the vendor.
3
What does ZDI-CAN-23254 affect?
ZDI-CAN-23254 affects installations of PaperCut MF specifically.
4
Who can exploit ZDI-CAN-23254?
Remote attackers can exploit ZDI-CAN-23254, but user interaction is required.
5
What must users do to be impacted by ZDI-CAN-23254?
To be impacted by ZDI-CAN-23254, users must visit a malicious page or open a malicious file.