CVE-2023-39143
Summary
| CVE | CVE-2023-39143 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-04 17:15:00 UTC |
| Updated | 2023-08-08 20:07:00 UTC |
| Description | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2023-39143: PaperCut Path Traversal/File Upload RCE Vulnerability – Horizon3.ai |
MISC |
www.horizon3.ai |
|
| PaperCut NG/MF Security Bulletin (July 2023) | PaperCut |
MISC |
www.papercut.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150719 PaperCut NG/MF Path Traversal Vulnerability (CVE-2023-39143)
- 378740 PaperCut NG/MF Chained Path Traversal in Authenticated API
- 730865 PaperCut NG/MF Chained Path Traversal Vulnerability (Unauthenticated Check)