CVE-2023-2508
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
20/09/2023
Last modified:
22/09/2023
Description
The `PaperCutNG Mobility Print` version 1.0.3512 application allows an<br />
<br />
unauthenticated attacker to perform a CSRF attack on an instance<br />
<br />
administrator to configure the clients host (in the "configure printer<br />
<br />
discovery" section). This is possible because the application has no<br />
<br />
protections against CSRF attacks, like Anti-CSRF tokens, header origin<br />
<br />
validation, samesite cookies, etc.<br />
<br />
<br />
<br />
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:papercut:mobility_print_server:1.0.3512:*:*:*:*:*:*:* | ||
| cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



