CVE-2023-2533 - PaperCut NG/MF
AI Vulnerability ContextA Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious l...
Overview
A source-backed snapshot of this vulnerability.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2023-2533
- Vendor/project
- PaperCut
- Product
- NG/MF
- Vulnerability name
- PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
- Date added
- 2025-07-28
- Due date
- 2025-08-18
- Known ransomware campaign use
- Unknown
- CVSS v3
- 8.4
Exploit context
What the vulnerability is about.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
