Path Traversal Vulnerability in PaperCut NG and MF by PaperCut
CVE-2023-31046
6.5MEDIUM
What is CVE-2023-31046?
A Path Traversal vulnerability exists in PaperCut NG and PaperCut MF versions prior to 22.1.1. This flaw allows an authenticated attacker, under certain conditions, to exploit the system by sending crafted requests that manipulate the file path. Specifically, it enables access to sensitive parts of the server's filesystem, potentially exposing critical information. The issue arises due to the way the static-content-files servlet handles requests that include directory traversal sequences like '/ui/static/..//..'.