CVE Vulnerabilities

CVE-2024-1883

Improper Neutralization of Equivalent Special Elements

Published: Mar 14, 2024 | Modified: Jan 23, 2025
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

Weakness

The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

Affected Software

NameVendorStart VersionEnd Version
Papercut_mfPapercut*20.1.10 (excluding)
Papercut_mfPapercut21.0.0 (including)21.2.14 (excluding)
Papercut_mfPapercut22.0.0 (including)22.1.5 (excluding)
Papercut_mfPapercut23.0.1 (including)23.0.7 (excluding)
Papercut_ngPapercut*20.1.10 (excluding)
Papercut_ngPapercut21.0.0 (including)21.2.14 (excluding)
Papercut_ngPapercut22.0.0 (including)22.1.5 (excluding)
Papercut_ngPapercut23.0.1 (including)23.0.7 (excluding)

Potential Mitigations

References