Description
This module exploits an authentication bypass in PaperCut NG and MF. A crafted Apache Tapestry complex-direct request invokes privileged ConfigEditor components through the public Home page. On version 26, the module reconfigures external user lookup to use an H2 JDBC URL whose initialization SQL evaluates Groovy code. On versions 24 and 25, it uses a bundled Derby procedure to write a temporary Groovy bootstrap class to the application classpath, then loads it as a database driver. The Java target serves an executable payload JAR and a generic memory-backed JAR loader over HTTP. Its payload classes and resources remain in memory; however, versions 24 and 25 still require the temporary Derby bootstrap class. The command targets execute a Windows or Linux command payload directly.
This module was successfully tested against: * PaperCut MF 26.0.4 (Build 76494) <-- emergency patch v1 * PaperCut NG 26.0.4 (Build 76495) <-- emergency patch v1 * PaperCut NG 26.0.3 (Build 76225) * PaperCut NG 25.0.11 (Build 75758) * PaperCut NG 24.1.9 (Build 73376)
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/papercut/ng_external_user_lookup_rcemsf undefined(ng_external_user_lookup_rce) > show actions ...actions...msf undefined(ng_external_user_lookup_rce) > set ACTION < action-name >msf undefined(ng_external_user_lookup_rce) > show options ...show and set options...msf undefined(ng_external_user_lookup_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub