CVE-2023-4568

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.
References
Link Resource
https://www.tenable.com/security/research/tra-2023-31 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*

History

15 Sep 2023, 16:20

Type Values Removed Values Added
References (MISC) https://www.tenable.com/security/research/tra-2023-31 - (MISC) https://www.tenable.com/security/research/tra-2023-31 - Exploit, Third Party Advisory
CPE cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-287
First Time Papercut papercut Ng
Papercut

14 Sep 2023, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-13 21:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-4568

Mitre link : CVE-2023-4568

CVE.ORG link : CVE-2023-4568


JSON object : View

Products Affected

papercut

  • papercut_ng
CWE
CWE-287

Improper Authentication