Medium severity6.5NVD Advisory· Published Oct 19, 2023· Updated Jun 17, 2026
CVE-2023-31046
CVE-2023-31046
Description
A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an authenticated attacker to achieve read-only access to the server's filesystem, because requests beginning with "GET /ui/static/..//.." reach getStaticContent in UIContentResource.class in the static-content-files servlet.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*range: <22.1.1
- (no CPE)range: <22.1.1
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*range: <22.1.1
- (no CPE)
- (no CPE)range: <22.1.1
Patches
Vulnerability mechanics
References
4- research.aurainfosec.io/disclosure/papercut/nvdThird Party Advisory
- web.archive.org/web/20230814061444/https://research.aurainfosec.io/disclosure/papercut/nvdThird Party Advisory
- www.papercut.com/kb/Main/PO-1216-and-PO-1219nvdVendor Advisory
- www.papercut.com/kb/Main/SecurityBulletinJune2023nvdVendor Advisory
News mentions
0No linked articles in our index yet.