PT-2023-25037 · Papercut · Papercut Ng

Published

2023-07-25

·

Updated

2023-07-31

·

CVE-2023-3486

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions PaperCut NG versions 22.0.12 and prior
Description An authentication bypass exists that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.
Recommendations For versions 22.0.12 and prior, update to a version later than 22.0.12 to resolve the issue. As a temporary workaround, consider restricting access to the file storage to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-3486

Affected Products

Papercut Ng