An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder.
Important: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.
Note:
This CVE has been split from CVE-2024-3037.
References
Link | Resource |
---|---|
https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Oct 2024, 15:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/ - Vendor Advisory | |
First Time |
Papercut
Papercut papercut Ng Papercut papercut Mf |
|
CPE | cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* |
26 Sep 2024, 13:32
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 Sep 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-26 02:15
Updated : 2024-10-03 15:19
NVD link : CVE-2024-8404
Mitre link : CVE-2024-8404
CVE.ORG link : CVE-2024-8404
JSON object : View
Products Affected
papercut
- papercut_ng
- papercut_mf
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')