CVE-2019-8948
9.8
CRITICAL · CVSS 3.0 · EPSS 3.9% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.93% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-02-20 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| papercut | papercut mf |
| papercut | papercut ng |
References
→ the Explorer · watch your stack · NVD