PoC Index

CVE-2023-4568

MEDIUM 6.5EPSS 3.6%

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
3.57% chance of exploitation in the next 30 days, 89th percentile
Nuclei
medium · CWE-287
Published
2023-09-13
Updated
2024-09-25

Proof-of-concept exploits (2)

Nuclei templates (1)

References

Related