CVE Vulnerabilities

CVE-2024-1883

Improper Neutralization of Equivalent Special Elements

Published: Mar 14, 2024 | Modified: Jan 23, 2025
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

Weakness

The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

Affected Software

Name Vendor Start Version End Version
Papercut_mf Papercut * 20.1.10 (excluding)
Papercut_mf Papercut 21.0.0 (including) 21.2.14 (excluding)
Papercut_mf Papercut 22.0.0 (including) 22.1.5 (excluding)
Papercut_mf Papercut 23.0.1 (including) 23.0.7 (excluding)
Papercut_ng Papercut * 20.1.10 (excluding)
Papercut_ng Papercut 21.0.0 (including) 21.2.14 (excluding)
Papercut_ng Papercut 22.0.0 (including) 22.1.5 (excluding)
Papercut_ng Papercut 23.0.1 (including) 23.0.7 (excluding)

Potential Mitigations

References