This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
- http://packetstormsecurity.com/files/171982/PaperCut-MF-NG-Authentication-Bypass-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/172022/PaperCut-NG-MG-22.0.4-Authentication-Bypass.html
- http://packetstormsecurity.com/files/172512/PaperCut-NG-MG-22.0.4-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/172780/PaperCut-PaperCutNG-Authentication-Bypass.html
- https://news.sophos.com/en-us/2023/04/27/increased-exploitation-of-papercut-drawing-blood-around-the-internet/
- https://github.com/0xB0y426/CVE-2023-27350-PoC
- https://github.com/0xfke/500-free-TryHackMe-rooms
- https://github.com/0ximan1337/CVE-2023-27350-POC
- https://github.com/ARESHAmohanad/THM
- https://github.com/ARESHAmohanad/tryhackme
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ASG-CASTLE/CVE-2023-27350
- https://github.com/AdamCrosser/awesome-vuln-writeups
- https://github.com/Aijoo100/Aijoo100
- https://github.com/BEPb/tryhackme
- https://github.com/FirikiIntelligence/Courses
- https://github.com/Hunterdii/TryHackMe-Roadmap
- https://github.com/Hunterdii/tryhackme-free-rooms
- https://github.com/Jenderal92/CVE-2023-27350
- https://github.com/Loginsoft-LLC/Linux-Exploit-Detection
- https://github.com/Loginsoft-Research/Linux-Exploit-Detection
- https://github.com/MaanVader/CVE-2023-27350-POC
- https://github.com/MinLouisCyber/500-free-TryHackMe-rooms
- https://github.com/Mr-xn/Penetration_Testing_POC
- https://github.com/Ossito/pentest-notes
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/Pari-Malam/CVE-2023-27350
- https://github.com/PudgyDragon/IOCs
- https://github.com/Royall-Researchers/CVE-2023-27350
- https://github.com/Saatann/cybersec-task3
- https://github.com/SenRanja/search-tweets-python
- https://github.com/Shayanschakravarthy/tryhackme-free-rooms
- https://github.com/Shinbatsu/awesome-tryhackme
- https://github.com/Shinbatsu/tryhackme-awesome
- https://github.com/SinMaven/BugSauce
- https://github.com/TamingSariMY/CVE-2023-27350-POC
- https://github.com/ThatNotEasy/CVE-2023-27350
- https://github.com/UNC1739/awesome-vulnerability-research
- https://github.com/abrahim7112/Vulnerability-checking-program-for-Android
- https://github.com/adhikara13/CVE-2023-27350
- https://github.com/adnan-kutay-yuksel/tryhackme-all-rooms-database
- https://github.com/arojit/cyber-expert-sft-rag-qwen
- https://github.com/arojit/model-training-with-sft
- https://github.com/dasarivarunreddy/free-rooms-tryhackme
- https://github.com/edwinantony1995/Tryhackme
- https://github.com/getdrive/PaperCut
- https://github.com/getdrive/PoC
- https://github.com/horizon3ai/CVE-2023-27350
- https://github.com/iluaster/getdrive_PoC
- https://github.com/imancybersecurity/CVE-2023-27350-POC
- https://github.com/imsalimansari/Try-Hack-Me-Roadmap
- https://github.com/komodoooo/Some-things
- https://github.com/komodoooo/some-things
- https://github.com/krazystar55/tryhackme
- https://github.com/kts262/ASM
- https://github.com/leejeeho6661/cve
- https://github.com/lions2012/Penetration_Testing_POC
- https://github.com/monke443/CVE-2023-27350
- https://github.com/nanasarpong024/tryhackme
- https://github.com/netlas-io/netlas-dorks
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/ochysbliss/My-Tryhackme-
- https://github.com/pentestfunctions/thm-room-points
- https://github.com/plzheheplztrying/cve_monitor
- https://github.com/rasan2001/CVE-2023-27350
- https://github.com/rasan2001/CVE-2023-27350-Ongoing-Exploitation-of-PaperCut-Remote-Code-Execution-Vulnerability
- https://github.com/rishabatra1802/TryHackMe_FreeRooms
- https://github.com/ronin-rb/example-exploits
- https://github.com/thmrevenant/tryhackme