CVE-2023-2533: PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.
Other sources
PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
PaperCut NG/MFfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is CVE-2023-2533?
CVE-2023-2533 is a Cross-Site Request Forgery (CSRF) vulnerability identified in PaperCut NG/MF.
What is the severity of CVE-2023-2533?
CVE-2023-2533 has a severity rating of 8.8 (High).
How can CVE-2023-2533 be exploited?
CVE-2023-2533 can be exploited by an attacker if the target is an admin with a current login session.
Which software versions are affected by CVE-2023-2533?
CVE-2023-2533 affects Papercut NG/MF version 22.0.10.
How do I fix the CVE-2023-2533 vulnerability?
To fix the CVE-2023-2533 vulnerability, update PaperCut NG/MF to a version that is not affected.