Impact
A vulnerability in the PaperCut NG/MF platform allows an authenticated administrator to supply a malicious script that escapes the embedded execution sandbox; this enables the attacker to run arbitrary operating‑system commands with administrative privileges on the host. The weakness arises from insufficient sanitization and inadequate access restrictions on the scripting subsystem, leading to code injection via the scripting interface.
Affected Systems
The affected product is PaperCut NG/MF. No specific version ranges are listed in the data, so all installations of PaperCut NG/MF that expose the scripting engine to an admin user are potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, which reduces confidence in current exploitation activity but does not eliminate the threat. The likely attack vector requires authenticated administrative access to the management interface, and successful exploitation would grant the attacker system‑level control over the host machine.
OpenCVE Enrichment