CVE-2023-4568
Summary
| CVE | CVE-2023-4568 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-13 21:15:00 UTC |
| Updated | 2023-09-15 16:20:00 UTC |
| Description | PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PaperCut NG Unauthenticated XMLRPC Functionality - Research Advisory | Tenable® |
MISC |
www.tenable.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150728 PaperCut NG/MF Unauthenticated XMLRPC Functionality (CVE-2023-4568)
- 731058 PaperCut NG/MF XMLRPC Improper Access Control Vulnerability