CVE-2024-1654

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/03/2024
Last modified:
23/01/2025

Description

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 20.1.10 (excluding)
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 21.0.0 (including) 21.2.14 (excluding)
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 22.0.0 (including) 22.1.5 (excluding)
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 23.0.1 (including) 23.0.7 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 20.1.10 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 21.0.0 (including) 21.2.14 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 22.0.0 (including) 22.1.5 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 23.0.1 (including) 23.0.7 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*