CVE-2024-1222
Incorrect authorization controls in PaperCut NG/MF APIs
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.
Esto permite a los atacantes utilizar una solicitud de API formada de forma maliciosa para obtener acceso a un nivel de autorización de API con privilegios elevados. Esto se aplica a un pequeño subconjunto de llamadas API de PaperCut NG/MF.
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the PrintDeployProxyController class. The issue results from the incorrect authorization. An attacker can leverage this vulnerability to bypass authentication on the system.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-02-05 CVE Reserved
- 2024-03-14 CVE Published
- 2024-06-19 EPSS Updated
- 2024-09-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-250: Execution with Unnecessary Privileges
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
PaperCut Search vendor "PaperCut" | PaperCut NG, PaperCut MF Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" | < 23.0.7 Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" and version " < 23.0.7" | en |
Affected
| ||||||
PaperCut Search vendor "PaperCut" | PaperCut NG, PaperCut MF Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" | < 22.1.5 Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" and version " < 22.1.5" | en |
Affected
| ||||||
PaperCut Search vendor "PaperCut" | PaperCut NG, PaperCut MF Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" | < 21.2.14 Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" and version " < 21.2.14" | en |
Affected
| ||||||
PaperCut Search vendor "PaperCut" | PaperCut NG, PaperCut MF Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" | < 20.1.10 Search vendor "PaperCut" for product "PaperCut NG, PaperCut MF" and version " < 20.1.10" | en |
Affected
|