Impact
An unsafe dynamic class loading flaw in the database connection utilities of PaperCut MF and PaperCut NG allows an attacker, with the ability to manipulate system configuration parameters, to instantiate arbitrary database driver classes. This leads to execution of arbitrary Java bytecode placed on the application classpath, running under the security context of the PaperCut server process. The vulnerability is a classic case of CWE‑470 and can be leveraged to compromise confidentiality, integrity, and availability of the affected infrastructure.
Affected Systems
The flaw affects PaperCut MF and PaperCut NG products published by PaperCut. No specific versions are enumerated in the advisory, implying that all deployed instances of these products could be vulnerable unless mitigated through configuration or patching.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.4, indicating critical severity. The EPSS score is < 1%, suggesting a very low current exploitation probability, yet the existence of the exploit, evidenced by the KEV listing, means the potential is non‑negligible. The vulnerability is listed in the CISA KEV catalog, confirming known exploitation potential. The likely attack vector is remote if configuration changes can be made over the network; otherwise, local attackers with editor rights to the configuration files can abuse it.
OpenCVE Enrichment