Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
Low
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
Low
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- PaperCut / PaperCut MF24.1.9
- PaperCut / PaperCut MF/NG0 – 24.1.10, 25.0.13, 26.0.5
- PaperCut / PaperCut MF/NG0 – 24.1.10
- PaperCut / PaperCut MF/NG25.0.0 – 25.0.13
- PaperCut / PaperCut MF/NG26.0.0 – 26.0.5
- PaperCut / PaperCut NG24.1.9
Exploits & proofs of concept
- nucleiPaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Directby darses,DhiyaneshDk
News coverage
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesThe Hacker News · 16d ago
Updated 9m ago · 8 sources