ZeroHour

CVE-2023-3486

CVSS 3.1
7.5 high
EPSS
79%p100
Published
()
Modified
Description

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.

Vendors
papercut
Products
papercut mf, papercut ng
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news