A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "20.1.8"
}
]
},
{
"events": [
{
"introduced": "21.0.0"
},
{
"fixed": "21.2.12"
}
]
},
{
"events": [
{
"introduced": "22.0.0"
},
{
"fixed": "22.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "20.1.8"
}
]
},
{
"events": [
{
"introduced": "21.0.0"
},
{
"fixed": "21.2.12"
}
]
},
{
"events": [
{
"introduced": "22.0.0"
},
{
"last_affected": "22.1.1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2533.json"