CVE-2023-39143 is a high-severity vulnerability affecting PaperCut NG and PaperCut MF for Windows before version 22.1.3. The issue is described as a combination of path traversal and file upload weaknesses that allows an unauthenticated attacker to read, upload, or delete arbitrary files on the PaperCut application server. In configurations where external device integration is enabled, the arbitrary file write capability can be leveraged to achieve remote code execution. The vulnerability is not characterized as a single-step RCE flaw, but rather as an exploit chain involving multiple issues that culminate in code execution under certain deployment conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a suite of Python scripts targeting PaperCut MF/NG print management software, focusing on vulnerabilities CVE-2023-39143 and CVE-2023-39469. The scripts provide a range of exploitation and post-exploitation capabilities: - CVE-2023-39143.py: Exploits a WebDAV/XML-RPC vulnerability to enumerate users, create scan jobs, and perform file upload/download via path traversal, potentially leading to remote code execution or sensitive file extraction. - CVE-2023-39469.py: Automates exploitation of a configuration injection vulnerability by manipulating the PaperCut admin interface to point to a malicious PostgreSQL server and XML file, enabling further attacks. - detect_papercut_version.py: Detects PaperCut servers and fingerprints their version using known image hashes. - papercut_download.py: Automates file download from the PaperCut WebDAV interface using path traversal and the COPY method. - papercut_hardcoded_creds.py: Tests a set of known hardcoded credentials against the PaperCut XML-RPC interface to identify valid accounts. - papercut_scan_docs_crawler.py and papercut_webdav_crawler.py: Recursively enumerate and download files from the PaperCut WebDAV interface, targeting scan jobs and other sensitive data. - papercut_webdav_brute.py: Brute-forces the 'papercut-webdav' account password using a 6-digit numeric code against the WebDAV endpoint. The scripts are modular and can be used independently or in sequence for reconnaissance, exploitation, and data extraction. The main attack vectors are network-based, leveraging HTTP(S) endpoints exposed by PaperCut. The repository is operational in maturity, providing working exploits and automation for real-world attacks. Endpoints such as '/webdav/', '/rpc/extdevice/xmlrpc', and '/app' are targeted, with file paths like '..\..\..\server.properties' and scan job directories being common exploitation targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A path traversal and file upload vulnerability in PaperCut MF/NG allowing unauthenticated attackers to read, delete, and upload files, potentially leading to RCE.
An unauthenticated path traversal + arbitrary file upload issue in PaperCut NG/MF that can lead to remote code execution in certain configurations (notably when external device integration is enabled).
Two path traversal vulnerabilities in PaperCut NG/MF that can allow arbitrary file read/write and potentially remote code execution when the external device setting is enabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.