ZDI-CAN-23481: ZDI-24-785: PaperCut MF EmailRenderer Server-Side Template Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut MF. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-1882.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23481?
The severity of ZDI-CAN-23481 is rated at 7.2 according to the CVSS.
How do I fix ZDI-CAN-23481?
To fix ZDI-CAN-23481, update your PaperCut MF installation to the latest patched version provided by the vendor.
What systems are affected by ZDI-CAN-23481?
ZDI-CAN-23481 affects installations of PaperCut MF where the authentication mechanism can be bypassed.
Can ZDI-CAN-23481 be exploited remotely?
Yes, ZDI-CAN-23481 can be exploited remotely by attackers who provide valid credentials.
What type of vulnerability is ZDI-CAN-23481?
ZDI-CAN-23481 is a code execution vulnerability that allows arbitrary code execution on affected systems.