Aller au contenu

Fiche vulnérabilité

CVE-2023-39143 : faille critique papercut papercut mf (CVSS 9.8)

Description

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
4 août 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • papercut papercut mf
  • papercut papercut ng

Références

Rechercher une autre vulnérabilité dans la base CVE