by @yosef0x1
21 Jun 2023

CVE-2023-27350 - Authentication Bypass in PaperCut

by @yosef0x1
21 Jun 2023

CVE-2023-27350 - Authentication Bypass in PaperCut

CVEs

9.8 Critical Severity

Apps

Papercut MF
Papercut MFPapercut
16.0.35130.*
16.0.34945.*
24.0.4.*
22.0.12.*
22.0.11.*
22.0.10.*
22.0.9.*
21.2.9.*
23.0.9.*
23.0.8.*
Papercut NG
Papercut NGPapercut
24.1.9.*
24.1.8.*
24.1.6.*
24.1.7.*
24.1.5.*
24.0.4.*
22.0.12.*
22.0.11.*
22.0.10.*
22.0.9.*

Screenshots from the blog posts

images/clj3lmml60phc0vnyht0va1pb.pngimages/clj3lmml60phc0vnyht0va1pb.png

Summary

In the detailed analysis of CVE-2023-27350, which was an interesting one, was gives unauthenticated access to the attacker by visiting an endpoint in the installation process. This access leads to bypassing the authentication mechanism. During this analysis, we will take a closer look at the code and debug it.

Description

users/photos/clun7lg6k7pi61ioc2abvc30b.jpg

@yosef0x1

54 posts

Security Researcher seeking for knowledge, hunger for more and more

Total vcoins

0

Badges

badges/images/cl1xi65zx02el0jms239bekpv.png

Malware Researcher

badges/images/clemwgql90gww0jnxh6rbcqsr.png

Memelord

Social media links

Comments (4)