CVE-2023-2533

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
PaperCut NG/MF, which, under specific conditions, could potentially enable
an attacker to alter security settings or execute arbitrary code. This could
be exploited if the target is an admin with a current login session. Exploiting
this would typically involve the possibility of deceiving an admin into clicking
a specially crafted malicious link, potentially leading to unauthorized changes.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Fluid AttacksCNA
8.4 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
papercutpapercut_mf
𝑥
< 20.1.8
papercutpapercut_mf
21.0.0 ≤
𝑥
< 21.2.12
papercutpapercut_mf
22.0.0 ≤
𝑥
< 22.1.1
papercutpapercut_ng
𝑥
< 20.1.8
papercutpapercut_ng
21.0.0 ≤
𝑥
< 21.2.12
papercutpapercut_ng
22.0.0 ≤
𝑥
≤ 22.1.1
𝑥
= Vulnerable software versions