Skip to main content

Improper Neutralization of Equivalent Special Elements

CVE-2024-1883

Severity Medium
Score 6.3/10

Summary

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • REQUIRED
  • NONE
  • LOW
  • LOW

CWE-76 - Improper Neutralization of Equivalent Special Elements

The software properly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

References

Advisory Timeline

  • Published