PT-2023-25037 · Papercut · Papercut Ng

CVE-2023-3486

·

Publicado

2023-07-25

·

Atualizado

2023-07-31

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions PaperCut NG versions 22.0.12 and prior
Description An authentication bypass exists that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.
Recommendations For versions 22.0.12 and prior, update to a version later than 22.0.12 to resolve the issue. As a temporary workaround, consider restricting access to the file storage to minimize the risk of exploitation.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3486

Produtos afetados

Papercut Ng