CVE-2024-1884: PaperCut MF
Medium severity, CVSS 6.5. EPSS: 37.9% chance of exploitation in the next 30 days.
This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
Affected products
- PaperCut PaperCut MF: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
- PaperCut PaperCut NG: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
Published 2024-03-14. Last modified 2026-06-17.