CVE-2023-4568

Scores

EPSS

0.752medium75.2%
0%20%40%60%80%100%

Percentile: 75.2%

CVSS

6.5medium3.x
0246810

CVSS Score: 6.5/10

All CVSS Scores

CVSS 3.x
6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-287

Related Vulnerabilities

Exploits

Exploit ID: CVE-2023-4568

Source: github-poc

URL: https://github.com/Cappricio-Securities/CVE-2023-4568

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: papercut_ng

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",      "versionEndIncluding": "22.0.12",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list