← Back to browse · API

CVE-2023-2533

Severity
HIGH
CVSS
8.4
EPSS
0.29246
Risk score
68.84
CISA KEV
Yes
PoC
No
Published
2023-06-20
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-34012, GHSA-FHF9-47GC-M9WC
Products
PaperCut:NG/MF, PaperCut:PaperCut NG/MF 22.0.10 <2.1.1
Sources
cisa.gov CVE-2023-2533
euvd EUVD-2023-34012

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.

References