CVE Vulnerabilities

CVE-2024-1883

Improper Neutralization of Equivalent Special Elements

Published: Mar 14, 2024 | Modified: Sep 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

Weakness

The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

Potential Mitigations

References