This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
Link | Tags |
---|---|
https://www.papercut.com/kb/Main/Security-Bulletin-March-2024 | vendor advisory |