CVE-2023-39143
CRITICAL 9.8EPSS 80.6%
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 80.62% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-22
- Published
- 2023-08-04
- Updated
- 2025-05-05
Proof-of-concept exploits (3)
- https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerabil…
- foregenix/CVE-2023-39143
- GodCuChu/DZ10