CVE-2023-39470: PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability
PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability.
The specific flaw exists within the management of the print.script.sandboxed setting. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20965.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39470?
CVE-2023-39470 has a high severity rating due to its ability to allow remote code execution on vulnerable PaperCut NG installations.
How do I fix CVE-2023-39470?
To fix CVE-2023-39470, upgrade PaperCut NG to version 22.1.1 or later, where the vulnerability has been addressed.
What type of attack is possible with CVE-2023-39470?
CVE-2023-39470 enables remote attackers to execute arbitrary code on systems running vulnerable versions of PaperCut NG.
Is authentication required to exploit CVE-2023-39470?
Yes, exploitation of CVE-2023-39470 requires authentication to the affected PaperCut NG installation.
Which versions of PaperCut are affected by CVE-2023-39470?
CVE-2023-39470 affects versions of PaperCut NG prior to 22.1.1.