Evidence used
- No CISA KEV confirmation is currently recorded.
- EPSS is 1.41% for the current model date.
BlackTreeCVE IntelligencePaperCut · PaperCut NG, PaperCut MF
High technical severity; prioritise exposed affected systems while verifying vendor guidance.
High technical severity; prioritise exposed affected systems while verifying vendor guidance.
Fix not verifiedThis vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
An attacker operating through a network path may attempt exploitation with elevated privileges. If successful, the issue may execute code or commands in the affected security context.
This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
An attacker operating through a network path may attempt exploitation with elevated privileges. If successful, the issue may execute code or commands in the affected security context.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-76: Improper Neutralization of Equivalent Special Elements. The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 14 Mar 2024 · Last source change 26 Sept 2024, 03:52 UTC · CWE-76 · Improper Neutralization of Equivalent Special Elements
Core structured fields are present and their contributing authorities are shown above.
No material field changes have been recorded since change tracking began. Routine source refreshes and cosmetic edits are intentionally excluded.