PaperCut Multiple Vulnerabilities
RISK: High Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in PaperCut. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.
Note:
CVE-2023-2533 is being exploited in the wild. A remote attacker could deceive an admin into clicking a specially crafted malicious link, potentially leading to remote code execution. Hence, the risk level is rated as High Risk.
Impact
- Remote Code Execution
- Information Disclosure
- Security Restriction Bypass
System / Technologies affected
- Versions prior to PaperCut NG/MF version 22.1.1
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- PaperCut NG/MF 22.1.1 or later versions
沒有留言:
發佈留言