Description
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
High
User Interaction
None
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
High
Integrity (Subsequent System)
High
Availability (Subsequent System)
High
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- PaperCut / PaperCut MF24.1.9
- PaperCut / PaperCut MF/NG0 – 24.1.10, 25.0.13, 26.0.5
- PaperCut / PaperCut MF/NG0 – 24.1.10
- PaperCut / PaperCut MF/NG25.0.0 – 25.0.13
- PaperCut / PaperCut MF/NG26.0.0 – 26.0.5
- PaperCut / PaperCut NG24.1.9
News coverage
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesThe Hacker News · 16d ago
Updated 9m ago · 8 sources