Lucene search

K
cve[email protected]CVE-2014-2659
HistoryApr 22, 2014 - 2:23 p.m.

CVE-2014-2659

2014-04-2214:23:35
CWE-352
web.nvd.nist.gov
28
cve-2014-2659
csrf
vulnerability
papercut mf
papercut ng
admin ui

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.7%

Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

Affected configurations

NVD
Node
papercutpapercut_mfRange14.1
OR
papercutpapercut_mfMatch12.0
OR
papercutpapercut_mfMatch12.1
OR
papercutpapercut_mfMatch12.2
OR
papercutpapercut_mfMatch12.3
OR
papercutpapercut_mfMatch12.4
OR
papercutpapercut_mfMatch12.5
OR
papercutpapercut_mfMatch13.0
OR
papercutpapercut_mfMatch13.1
OR
papercutpapercut_mfMatch13.2
OR
papercutpapercut_mfMatch13.3
OR
papercutpapercut_mfMatch13.4
OR
papercutpapercut_mfMatch13.5
OR
papercutpapercut_mfMatch14.0
OR
papercutpapercut_ngRange14.1
OR
papercutpapercut_ngMatch12.0
OR
papercutpapercut_ngMatch12.1
OR
papercutpapercut_ngMatch12.2
OR
papercutpapercut_ngMatch12.3
OR
papercutpapercut_ngMatch12.4
OR
papercutpapercut_ngMatch12.5
OR
papercutpapercut_ngMatch13.0
OR
papercutpapercut_ngMatch13.1
OR
papercutpapercut_ngMatch13.2
OR
papercutpapercut_ngMatch13.3
OR
papercutpapercut_ngMatch13.4
OR
papercutpapercut_ngMatch13.5
OR
papercutpapercut_ngMatch14.0

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.7%

Related for CVE-2014-2659