Show filters
26 Total Results
Displaying 21-26 of 26
Sort by:
Attacker Value
Unknown

CVE-2023-2533

Disclosure Date: June 20, 2023 (last updated October 08, 2023)
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.
Attacker Value
Unknown

CVE-2023-27351

Disclosure Date: April 20, 2023 (last updated October 08, 2023)
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.
Attacker Value
Unknown

CVE-2019-12135

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.
0
Attacker Value
Unknown

CVE-2019-8948

Disclosure Date: February 20, 2019 (last updated November 27, 2024)
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
0
Attacker Value
Unknown

CVE-2014-2658

Disclosure Date: April 28, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Papercut MF and NG before 14.1 (Build 26983) allows attacker to cause a denial of service via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-2659

Disclosure Date: April 22, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0