CVE-2023-4568

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
13/09/2023
Last modified:
15/09/2023

Description

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 22.0.12 (including)


References to Advisories, Solutions, and Tools