← Back to browse · API

CVE-2023-39143

Severity
CRITICAL
CVSS
9.8
EPSS
0.80292
Risk score
67.3
CISA KEV
No
PoC
No
Published
2023-08-04
Modified
2025-05-05
First seen
2026-08-07
Aliases
EUVD-2023-42884, GHSA-MM5W-GQW5-M4QX
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-42884

Description

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

References