Unauthorized write operations in PaperCut NG/MF
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 1.3%
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
PaperCut · PaperCut NG, PaperCut MF