CVE-2024-9672

A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*

History

30 Jan 2025, 14:55

Type Values Removed Values Added
References () https://www.papercut.com/kb/Main/security-bulletin-december-2024/ - () https://www.papercut.com/kb/Main/security-bulletin-december-2024/ - Vendor Advisory
CWE CWE-79
First Time Papercut papercut Mf
Papercut
Papercut papercut Ng
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) Existe una vulnerabilidad de Cross Site Scripting (XSS) reflejado en PaperCut NG/MF. Este problema se puede aprovechar para ejecutar payloads de JavaScript manipuladas especialmente en el navegador. El usuario debe hacer clic en un enlace malicioso para que se produzca este problema.
CPE cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*

10 Dec 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 00:15

Updated : 2025-01-30 14:55


NVD link : CVE-2024-9672

Mitre link : CVE-2024-9672

CVE.ORG link : CVE-2024-9672


JSON object : View

Products Affected

papercut

  • papercut_mf
  • papercut_ng
CWE
CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')