CVE-2023-2533

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
20/06/2023
Last modified:
29/07/2025

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in<br /> PaperCut NG/MF, which, under specific conditions, could potentially enable<br /> an attacker to alter security settings or execute arbitrary code. This could<br /> be exploited if the target is an admin with a current login session. Exploiting<br /> this would typically involve the possibility of deceiving an admin into clicking<br /> a specially crafted malicious link, potentially leading to unauthorized changes.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 20.1.8 (excluding)
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 21.0.0 (including) 21.2.12 (excluding)
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* 22.0.0 (including) 22.1.1 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 20.1.8 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 21.0.0 (including) 21.2.12 (excluding)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* 22.0.0 (including) 22.1.1 (including)