CVE-2024-1222
HIGHDescription
This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.
Is your site exposed to CVE-2024-1222?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| papercut | papercut_mf |
| papercut | papercut_mf |
| papercut | papercut_mf |
| papercut | papercut_mf |
| papercut | papercut_ng |
| papercut | papercut_ng |
| papercut | papercut_ng |
| papercut | papercut_ng |
| apple | macos |
| linux | linux_kernel |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2024-1222? +
How severe is CVE-2024-1222? +
What products are affected by CVE-2024-1222? +
How do I check if I'm vulnerable to CVE-2024-1222? +
Related Vulnerabilities
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power …
mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An …
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS …
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue …
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue …
The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution …