← Back to browse · API

CVE-2023-3486

Severity
HIGH
CVSS
8.2
EPSS
0.79159
Risk score
60.51
CISA KEV
No
PoC
No
Published
2023-07-25
Modified
2024-10-23
First seen
2026-08-07
Aliases
EUVD-2023-44145, GHSA-C382-PG7W-VXGR
Products
PaperCut:PaperCut NG 0 <22.1.3
Sources
euvd EUVD-2023-44145

Description

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.

References