PaperCut NG
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*
- < 25.0.10
A cross-site scripting (XSS) vulnerability has been identified in PaperCut NG/MF versions prior to 25.0.10. This vulnerability allows authenticated administrator users to inject arbitrary web scripts or HTML into various UI fields. Exploitation of this issue could compromise the sessions of other administrators or enable unauthorized actions within the context of an administrator's active login.
Exploitation of this vulnerability could lead to the execution of malicious scripts in an administrator's browser session, potentially allowing for session hijacking or unauthorized actions on behalf of the administrator.
Users are advised to upgrade to PaperCut NG/MF version 25.0.10. For Konica Minolta fleets using PaperCut MF, ensure the embedded application is updated to version 25.0.5 (Standard) or 25.0.9 (Certified).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.