CVE-2024-9672

A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*

History

30 Jan 2025, 14:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Papercut
Papercut papercut Ng
Papercut papercut Mf
Summary
  • (es) Existe una vulnerabilidad de Cross Site Scripting (XSS) reflejado en PaperCut NG/MF. Este problema se puede aprovechar para ejecutar payloads de JavaScript manipuladas especialmente en el navegador. El usuario debe hacer clic en un enlace malicioso para que se produzca este problema.
CPE cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
CWE CWE-79
References () https://www.papercut.com/kb/Main/security-bulletin-december-2024/ - () https://www.papercut.com/kb/Main/security-bulletin-december-2024/ - Vendor Advisory

10 Dec 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 00:15

Updated : 2025-01-30 14:55


NVD link : CVE-2024-9672

Mitre link : CVE-2024-9672

CVE.ORG link : CVE-2024-9672


JSON object : View

Products Affected

papercut

  • papercut_ng
  • papercut_mf
CWE
CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')