CVE-2023-39143: Path Traversal
PaperCut NG and PaperCut MF before 22.1.3 are vulnerable to path traversal which enables attackers to read, delete, and upload arbitrary files.
Other sources
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39143?
CVE-2023-39143 is a vulnerability that affects PaperCut NG and PaperCut MF versions prior to 22.1.3 on Windows, allowing path traversal and enabling attackers to upload, read, or delete arbitrary files, leading to remote code execution.
How severe is CVE-2023-39143?
CVE-2023-39143 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2023-39143?
PaperCut NG and PaperCut MF versions prior to 22.1.3 on Windows are affected by CVE-2023-39143.
How can attackers exploit CVE-2023-39143?
Attackers can exploit CVE-2023-39143 by using path traversal to upload, read, or delete arbitrary files, leading to potential remote code execution.
Where can I find more information about CVE-2023-39143?
You can find more information about CVE-2023-39143 at the following references: [Reference 1](https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/) and [Reference 2](https://www.papercut.com/kb/Main/securitybulletinjuly2023/).