6.5
CVSSv3

CVE-2023-31046

Published: 19/10/2023 Updated: 26/10/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A Path Traversal vulnerability exists in PaperCut NG prior to 22.1.1 and PaperCut MF prior to 22.1.1. Under specific conditions, this could potentially allow an authenticated malicious user to achieve read-only access to the server's filesystem, because requests beginning with "GET /ui/static/..//.." reach getStaticContent in UIContentResource.class in the static-content-files servlet.

Vulnerable Product Search on Vulmon Subscribe to Product

papercut papercut mf

papercut papercut ng