imPC@ndo IT

Tracker / CVE-2023-39143

CVE-2023-39143

Critical 9.8

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

Affected products and versions

papercut papercut_mf · … → 22.1.3
papercut papercut_ng · … → 22.1.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References