CVE-2024-9672: PaperCut MF
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.
Affected products
- PaperCut PaperCut MF: before 24.1.1 (fixed in 24.1.1)
- PaperCut PaperCut NG: before 24.1.1 (fixed in 24.1.1)
Published 2024-12-10. Last modified 2026-06-17.