CyberRota Analysis
AI-GeneratedAn unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut MF and NG allows attackers to execute arbitrary Java bytecode by manipulating system configuration parameters, as the application fails to validate driver names against an allowlist. This critical flaw, with a CVSS score of 9.4, poses a significant risk to organizations using these products, particularly those with exposed configurations. Organizations utilizing PaperCut MF or NG should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Related CVEs
Other vulnerabilities affecting the same vendor(s)