
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-1221 is a vulnerability in PaperCut NG/MF that potentially allows files on a server to be exposed using a specifically formed payload against the impacted API endpoint. The vulnerability specifically affects Linux and macOS PaperCut NG/MF servers, and requires an attacker to perform reconnaissance to gain knowledge of a system token (CVE Mitre).
The vulnerability has been assigned a CVSS score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). The specific flaw exists within the upload endpoint, where an attacker can abuse the service to read arbitrary files by uploading a symbolic link. While authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. An attacker can leverage this vulnerability to disclose information in the context of root (ZDI Advisory).
The vulnerability allows remote attackers to disclose sensitive information on affected installations of PaperCut NG. The impact is primarily focused on information disclosure, with the potential for attackers to read arbitrary files on the system with root-level access (ZDI Advisory).
The vulnerability requires authentication to exploit, although the existing authentication mechanism can be bypassed. The attacker must perform reconnaissance to gain knowledge of a system token before exploitation is possible (CVE Mitre).
PaperCut has issued an update to correct this vulnerability. Users should apply the latest security updates to their PaperCut NG/MF installations to mitigate this vulnerability (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."