CVE-2023-2508

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
20/09/2023
Last modified:
22/09/2023

Description

The `PaperCutNG Mobility Print` version 1.0.3512 application allows an<br /> <br /> unauthenticated attacker to perform a CSRF attack on an instance<br /> <br /> administrator to configure the clients host (in the "configure printer<br /> <br /> discovery" section). This is possible because the application has no<br /> <br /> protections against CSRF attacks, like Anti-CSRF tokens, header origin<br /> <br /> validation, samesite cookies, etc.<br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:papercut:mobility_print_server:1.0.3512:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*