Page 4 of 26 results (0.004 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists within the External User Lookup functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute Java code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. • https://www.papercut.com/kb/Main/SecurityBulletinJuly2023 https://www.zerodayinitiative.com/advisories/ZDI-23-1285 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.8EPSS: 89%CPEs: 3EXPL: 2

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration). PaperCut NG y PaperCut MF antes de 22.1.3 en Windows permiten atravesar rutas, lo que permite a los atacantes cargar, leer o eliminar archivos arbitrarios. Esto conduce a la ejecución remota de código cuando la integración de dispositivos externos está habilitada (una configuración muy común). • https://github.com/codeb0ss/CVE-2023-39143 https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability https://www.papercut.com/kb/Main/securitybulletinjuly2023 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 8.2EPSS: 0%CPEs: 2EXPL: 0

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected. Existe una omisión de autenticación en las versiones 22.0.12 y anteriores de PaperCut NG que podría permitir a un atacante no remoto no autenticado cargar archivos arbitrarios en el almacenamiento del host de PaperCut NG. Esto podría agotar los recursos del sistema e impedir que el servicio funcione como se espera. • https://www.papercut.com/kb/Main/SecurityBulletinJuly2023 https://www.tenable.com/security/research/tra-2023-23 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 1

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes. • https://fluidattacks.com/advisories/arcangel https://www.papercut.com/kb/Main/SecurityBulletinJune2023 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 9.8EPSS: 96%CPEs: 6EXPL: 13

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. • https://github.com/horizon3ai/CVE-2023-27350 https://www.exploit-db.com/exploits/51391 https://www.exploit-db.com/exploits/51452 https://github.com/adhikara13/CVE-2023-27350 https://github.com/imancybersecurity/CVE-2023-27350-POC https://github.com/ThatNotEasy/CVE-2023-27350 https://github.com/Jenderal92/CVE-2023-27350 https://github.com/MaanVader/CVE-2023-27350-POC https://github.com/ASG-CASTLE/CVE-2023-27350 https://github.com/rasan2001/CVE-2023-27350-Ongoing-Exploitation-o • CWE-284: Improper Access Control •