CVE-2024-9672
MEDIUMDescription
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.
Is your site exposed to CVE-2024-9672?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| papercut | papercut_mf |
| papercut | papercut_ng |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-9672? +
How severe is CVE-2024-9672? +
What products are affected by CVE-2024-9672? +
How do I check if I'm vulnerable to CVE-2024-9672? +
Related Vulnerabilities
An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.
ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications …
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when …
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but …
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the …
Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …