CVE-2023-39143
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
- Affected products
- Papercut Mf, Papercut Ng
- Papercut Papercut Mf
- < 22.1.3
- Papercut Papercut Ng
- < 22.1.3
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 80.6% (100th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2023-08-04
CVE-2023-39143 at NVD
1 known exploit for CVE-2023-39143
Proof-of-concept code and exploit modules indexed by Sploitus