PaperCut MF 和 PaperCut NG 数据库连接工具中存在一个不安全的动态类加载漏洞。该应用程序会根据可配置的驱动程序名称来实例化数据库驱动类,但并未针对已批准驱动程序的允许列表进行验证。如果攻击者能够操纵系统配置参数,就能够在 PaperCut 服务器进程的安全上下文中,执行位于应用程序类路径中的任意 Java 字节码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PaperCut | PaperCut MF/NG | < 24.1.10, 25.0.13, 26.0.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PaperCut | PaperCut MF/NG | 0 ~ 24.1.10, 25.0.13, 26.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet