Vulnerabilidades en PaperCut

29 resultados
Análisis Vexday

PaperCut apresenta um portfólio moderado de 27 vulnerabilidades com 3 atualmente sob ataque ativo, indicando risco operacional imediato. Apesar de apenas 1 crítica, a recentidade é preocupante: 4 CVEs nos últimos 90 dias e a dominância de CWE-76 (injeção) sugerem padrão de defeitos exploráveis em lógica de aplicação. Organizações usuárias devem priorizar patches recentes e monitorar os 3 CVEs em exploração ativa.

CVE-2023-27350CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). AuthenticEPSS 100.0%KEVCVE-2023-3486HIGHPaperCut NG Unauthenticated File UploadEPSS 79.2%CVE-2023-27351HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). AuthenticEPSS 77.4%KEVCVE-2024-1222HIGHIncorrect authorization controls in PaperCut NG/MF APIsEPSS 64.0%CVE-2024-1883MEDIUMReflected XSS in PaperCut NG/MFEPSS 61.5%CVE-2023-39469HIGHPaperCut NG External User Lookup Code Injection Remote Code Execution VulnerabilityEPSS 58.1%CVE-2024-1884MEDIUMServer Side Request Forgery in PaperCut NG/MFEPSS 37.9%CVE-2023-2533HIGHPaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFEPSS 29.2%KEVCVE-2023-4568MEDIUMPaperCut NG Unauthenticated XMLRPCEPSS 3.6%CVE-2023-39470HIGHPaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-1882HIGHServer-side resource injection in PaperCut NG/MFEPSS 1.4%CVE-2024-1654HIGHUnauthorized write operations in PaperCut NG/MFEPSS 1.3%CVE-2026-8793MEDIUMPaperCut NG/MF: Insufficient brute-force protectionEPSS 0.7%CVE-2026-8794MEDIUMPaperCut NG/MF: User enumeration via timing attackEPSS 0.7%CVE-2026-6418MEDIUMPaperCut NG/MF: Path Traversal in Shared Account SynchronizationEPSS 0.6%CVE-2024-1221LOWImproper access controls on APIs on Linux and macOS in PaperCut NG/MFEPSS 0.5%CVE-2024-1223MEDIUMImproper authorization controls in PaperCut NG/MFEPSS 0.4%CVE-2024-4712HIGHArbitrary File Creation in PaperCut NG/MF Web Print Image HandlerEPSS 0.4%CVE-2024-3037HIGHArbitrary File Deletion in PaperCut NG/MF Web PrintEPSS 0.4%CVE-2024-8404HIGHArbitrary File Deletion in PaperCut NG/MF Web Print Hot folderEPSS 0.4%