cve/2024/CVE-2024-8405.md
2025-09-29 21:09:30 +02:00

18 lines
1017 B
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-8405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8405)
![](https://img.shields.io/static/v1?label=Product&message=PaperCut%20NG%2C%20PaperCut%20MF&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-77%20Improper%20Neutralization%20of%20Special%20Elements%20used%20in%20a%20Command%20('Command%20Injection')&color=brightgreen)
### Description
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that dont exist when a maliciously formed payload is provided. This can be used to flood disk space and result in a Denial of Service (DoS) attack.Note: This CVE has been split from CVE-2024-4712.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds