CVE-2014-2659: PaperCut MF
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Affected products
- PaperCut PaperCut MF: up to and including 14.1; version 12.0 only; version 12.1 only; version 12.2 only; version 12.3 only; version 12.4 only; …
- PaperCut PaperCut NG: up to and including 14.1; version 12.0 only; version 12.1 only; version 12.2 only; version 12.3 only; version 12.4 only; …
Published 2014-04-22. Last modified 2026-06-17.