Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjg5-wj9r-9mfx

Опубликовано: 28 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.1

Описание

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

EPSS

Процентиль: 89%
0.03574
Низкий

9.4 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 9.1
nvd
27 дней назад

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

CVSS3: 9.1
fstec
29 дней назад

Уязвимость программных средств контроля за печатью в сети PaperCut MF и PaperCut NG, связанная с небезопасной динамической загрузкой классов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 89%
0.03574
Низкий

9.4 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-470