CVE-2023-4568
MediumPublished
PaperCut NG Unauthenticated XMLRPC
- Published
- Sep 13, 2023
- Updated
- Sep 25, 2024
- Assigning CNA
- tenable
- Evidence observed
- Aug 7, 2026
Primary CVSS
6.5/ 10Medium
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N3.9%
Low · next 30 days
- Percentile
- 89.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.
Sources
1- CVE-2023-4568Scanner
PaperCut NG Unauthenticated XMLRPC Functionality
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.