References https://nvd.nist.gov/vuln/detail/CVE-2023-39469 https://www.papercut.com/kb/Main/SecurityBulletinJune2023/ https://www.papercut.com/kb/Main/security-vulnerability-log/ https://github.com/advisories/GHSA-h7m6-3v2j-jm33 https://www.papercut.com/kb/Main/SecurityBulletinJuly2023/ https://advisories.checkpoint.com/defense/advisories/public/2024/cpai-2023-1182.html https://www.hkcert.org/security-bulletin/papercut-multiple-vulnerabilities_20250729 https://orionx.foregenix.com/blog/exploiting-cve-2023-39143 https://access.redhat.com/security/cve/cve-2023-39469 https://app.opencve.io/cve/?vendor=papercut
Related VulnerabilitiesPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-DirectPaperCut NG/MF /rpc/api/rest/master/user/createInternalUser;/keepalive 权限绕过漏洞 (CVE-2023-27351)PoCCVE-2023-27351: PaperCut NG - Authentication BypassPoCCVE-2023-27350: PaperCut - Unauthenticated Remote Code ExecutionPoCCVE-2023-39143: PaperCut < 22.1.3 - Path TraversalPoCCVE-2023-4568: PaperCut NG Unauthenticated XMLRPC FunctionalityPoCpapercut-log4j-rce: Papercut - Remote Code Execution (Apache Log4j)PaperCut NG 允许运行未经身份验证的 XMLRPC 命令(CVE-2023-4568)PaperCut NG 未授权XMLRPC命令执行漏洞PaperCut NG FileUploadAuthenticationFilter 认证绕过漏洞PaperCut NG SetupCompleted 认证绕过漏洞 (获取session)PaperCut NG SetupCompleted 认证绕过漏洞 (代码执行)