CVE-2023-2533
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
20/06/2023
Last modified:
29/07/2025
Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in<br />
PaperCut NG/MF, which, under specific conditions, could potentially enable<br />
an attacker to alter security settings or execute arbitrary code. This could<br />
be exploited if the target is an admin with a current login session. Exploiting<br />
this would typically involve the possibility of deceiving an admin into clicking<br />
a specially crafted malicious link, potentially leading to unauthorized changes.<br />
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* | 20.1.8 (excluding) | |
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* | 21.0.0 (including) | 21.2.12 (excluding) |
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* | 22.0.0 (including) | 22.1.1 (excluding) |
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* | 20.1.8 (excluding) | |
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* | 21.0.0 (including) | 21.2.12 (excluding) |
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* | 22.0.0 (including) | 22.1.1 (including) |
To consult the complete list of CPE names with products and versions, see this page