ZeroHour

CVE-2023-39143

PoC 1
CVSS 3.1
9.8 critical
EPSS
81%p100
Published
()
Modified
Description

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

Vendors
papercut
Products
papercut mf, papercut ng
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news