PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.
References
Link | Resource |
---|---|
https://www.tenable.com/security/research/tra-2023-31 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-09-13 21:15
Updated : 2023-09-15 16:20
NVD link : CVE-2023-4568
Mitre link : CVE-2023-4568
CVE.ORG link : CVE-2023-4568
JSON object : View
Products Affected
papercut
- papercut_ng
CWE
CWE-287
Improper Authentication