Vulnerability record · CVE-2024-1883 · published 14 March 2024
CVE-2024-1883: PaperCut NG/MF reflected XSS via crafted URL
Papercut · Papercut Mf
PaperCut NG and MF contain a reflected cross-site scripting flaw in the application server. An attacker can craft a malicious URL containing a script; when a user clicks it, the script executes in the user's browser context. This matters because it can lead to limited loss of confidentiality, integrity, or availability.
Description
This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 medium severity with user interaction required, but high EPSS percentile suggests elevated exploitation likelihood.
What it is
PaperCut NG and MF contain a reflected cross-site scripting flaw in the application server. An attacker can craft a malicious URL containing a script; when a user clicks it, the script executes in the user's browser context. This matters because it can lead to limited loss of confidentiality, integrity, or availability.
Impact
An attacker can execute script in a victim's browser session, potentially stealing session data or performing actions as the user. The CVSS vector rates confidentiality and integrity impact as low, with no availability impact.
Attack surface
Reached over the network via a crafted URL; no authentication is required, but the victim must click the link (user interaction required). The scope is changed, meaning the script can affect resources beyond the vulnerable component.
Exploitation
Not listed in CISA KEV. EPSS probability is 0.61472 (99.126th percentile), indicating high predicted likelihood of exploitation activity, but no public exploit or in-the-wild confirmation is provided in the record.
What to do
- Apply the vendor patch referenced in the PaperCut Security Bulletin March 2024.
- If patching is delayed, restrict network access to the PaperCut application server to trusted users and networks.
- Deploy a web application firewall or input filtering to block script payloads in reflected parameters.
- Train users not to click unsolicited links to the PaperCut server.
- Review and harden browser security settings where feasible to reduce script execution impact.
Detection
- Monitor web server logs for requests containing script tags or encoded script payloads in URL parameters.
- Alert on unusual referrer or URL patterns targeting PaperCut endpoints with reflected input.
- Review authentication and session logs for anomalous activity following suspicious link clicks.
- Use endpoint or browser telemetry to detect unexpected script execution in PaperCut user sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.papercut.com/kb/Main/Security-Bulletin-March-2024 | Vendor Advisory |
| https://www.papercut.com/kb/Main/Security-Bulletin-March-2024 | Vendor Advisory |
Track CVE-2024-1883 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.