PaperCut NG/MF Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in PaperCut NG/MF versions prior to 25.0.10. This vulnerability allows authenticated administrator users to inject arbitrary web scripts or HTML into various UI fields. Exploitation of this issue could compromise the sessions of other administrators or enable unauthorized actions within the context of an administrator's active login.

Impact

Exploitation of this vulnerability could lead to the execution of malicious scripts in an administrator's browser session, potentially allowing for session hijacking or unauthorized actions on behalf of the administrator.

Remediation

Users are advised to upgrade to PaperCut NG/MF version 25.0.10. For Konica Minolta fleets using PaperCut MF, ensure the embedded application is updated to version 25.0.5 (Standard) or 25.0.9 (Certified).

Added: Mar 31, 2026, 1:19 AM
Updated: Mar 31, 2026, 1:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
5.4
exploitability
2.4
remediation
7.7
relevance
5.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.