VulnerabilityModified
CVE-2023-39143
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.
CRITICAL 9.8EPSS 80.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 80.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 80.62% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- papercut/papercut mf · papercut/papercut ng
- Source
- cve@mitre.org
References
- https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/Exploit, Third Party Advisory
- https://www.papercut.com/kb/Main/securitybulletinjuly2023/Vendor Advisory
- https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/Exploit, Third Party Advisory
- https://www.papercut.com/kb/Main/securitybulletinjuly2023/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.