PT-2023-2482 · Unknown · Papercut Ng
Published
2023-03-14
·
Updated
2025-07-23
·
CVE-2023-27350
10
Critical
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
The vulnerable software is PaperCut NG, specifically version 22.0.5 (Build 63914). This version is affected by an improper access control flaw in the SetupCompleted class, which allows remote attackers to bypass authentication and execute arbitrary code in the context of SYSTEM.
An exploit for this issue exists and has been used by malicious software such as LockBit and Clop.
The issue can be exploited without requiring authentication, making it a significant concern for users of the affected software.
There are approximately 4,929 results related to this vulnerability on ZoomEye, indicating a potentially large number of affected systems.
More information about the exploit can be found on various online platforms, including Reddit and TryHackMe.
https://www.reddit.com/r/netsec/comments/12xc9r7/papercut cve202327350 deep dive indicators of/
#PaperCut #RemoteCodeExecution #ImproperAccessControl #Cybersecurity #TryHackMe #Exploit #LockBit #Clop #ZoomEye
Exploit
Fix
RCE
Improper Access Control
Weakness Enumeration
Related Identifiers
Affected Products
References · 102
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/papercut_ng_auth_bypass.rb⭐ 34302 🔗 14014 · Exploit
- 🔥 https://github.com/horizon3ai/CVE-2023-27350⭐ 47 🔗 19 · Exploit
- 🔥 https://github.com/0ximan1337/CVE-2023-27350-POC⭐ 12 🔗 5 · Exploit
- 🔥 https://github.com/TamingSariMY/CVE-2023-27350-POC⭐ 12 🔗 5 · Exploit
- 🔥 https://github.com/imancybersecurity/CVE-2023-27350-POC⭐ 12 🔗 5 · Exploit
- 🔥 https://github.com/adhikara13/CVE-2023-27350⭐ 8 🔗 3 · Exploit
- 🔥 https://github.com/MaanVader/CVE-2023-27350-POC⭐ 5 🔗 2 · Exploit
- 🔥 https://github.com/ThatNotEasy/CVE-2023-27350⭐ 3 🔗 3 · Exploit
- 🔥 https://github.com/Pari-Malam/CVE-2023-27350⭐ 3 🔗 3 · Exploit
- 🔥 https://exploit-db.com/exploits/51391 · Exploit
- 🔥 http://packetstormsecurity.com/files/172780/PaperCut-PaperCutNG-Authentication-Bypass.html · Exploit
- 🔥 http://packetstormsecurity.com/files/172022/PaperCut-NG-MG-22.0.4-Authentication-Bypass.html · Exploit
- 🔥 https://exploit-db.com/exploits/51452 · Exploit
- 🔥 http://packetstormsecurity.com/files/172512/PaperCut-NG-MG-22.0.4-Remote-Code-Execution.html · Exploit
- https://bdu.fstec.ru/vul/2023-02273 · Security Note