CVE-2024-1883: PaperCut MF

Medium severity, CVSS 6.1. EPSS: 61.5% chance of exploitation in the next 30 days.

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

Affected products

  • PaperCut PaperCut MF: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
  • PaperCut PaperCut NG: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)

Published 2024-03-14. Last modified 2026-06-17.