PaperCut NG是澳大利亚PaperCut公司的一套下一代打印机控制软件。 PaperCut NG/MF存在安全漏洞,该漏洞源于存在服务器端请求伪造(SSRF)漏洞,允许攻击者诱导服务器端应用程序向攻击者选择的任意域发出HTTP请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PaperCut | PaperCut NG, PaperCut MF | 0 ~ 23.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-1222 | 8.6 HIGH | Incorrect authorization controls in PaperCut NG/MF APIs |
| CVE-2024-1654 | 7.2 HIGH | Unauthorized write operations in PaperCut NG/MF |
| CVE-2024-1882 | 7.2 HIGH | Server-side resource injection in PaperCut NG/MF |
| CVE-2024-1883 | 6.3 MEDIUM | Reflected XSS in PaperCut NG/MF |
| CVE-2024-1223 | 4.8 MEDIUM | Improper authorization controls in PaperCut NG/MF |
| CVE-2024-1221 | 3.1 LOW | Improper access controls on APIs on Linux and macOS in PaperCut NG/MF |
No comments yet