Improper access control in PaperCut NG and PaperCut MF - CVE-2023-27350
Published: April 24, 2023 / Updated: October 28, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the SetupCompleted class. A remote non-authenticated attacker can bypass authentication process and execute arbitrary code with SYSTEM privileges.
Affected software
PaperCut MF
How to mitigate CVE-2023-27350
PaperCut MF - addressed in versions 20.1.7, 21.2.11, 22.0.9
Links to Public Exploits and PoC-codes
- Exploit #10774 - CVE-2023-27350-POC () (October 28, 2024)
- Exploit #10709 - PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE) (October 25, 2024)
- Exploit #10710 - PaperCut NG/MG 22.0.4 - Authentication Bypass (October 25, 2024)
- Exploit #9800 - CVE-2023-27350 (Perfom With Massive Authentication Bypass In PaperCut MF/NG) (May 13, 2024)
- Exploit #9094 - PaperCut PaperCutNG Authentication Bypass (June 7, 2023)
- Exploit #9006 - CVE-2023-27350 (Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking) (April 26, 2023)
- Exploit #9003 - CVE-2023-27350 (Proof of Concept Exploit for PaperCut CVE-2023-27350) (April 24, 2023)