CVE-2023-39143
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 80%
from disclosure to weapon797 days
Published on NVDAug 4
1st PoC+797d
VulnCheck+805d
exploitation probability
80%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/foregenix/CVE-2023-39143★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.