CVE-2023-39143

Scores

EPSS

0.882high88.2%
0%20%40%60%80%100%

Percentile: 88.2%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-22

Exploits

Exploit ID: CVE-2023-39143

Source: github-poc

URL: https://github.com/foregenix/CVE-2023-39143

Vulnerable Software (2)

Type: Configuration

Vendor: *

Product: papercut_mf

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",          "versionEndExcluding": "22.1.3",          "vulnerable": true ...

Source: nvd

Type: Configuration

Vendor: *

Product: papercut_ng

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",          "versionEndExcluding": "22.1.3",          "vulnerable": true ...

Source: nvd

End of list