CVE-2023-2508

The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section). This is possible because the application has no protections against CSRF attacks, like Anti-CSRF tokens, header origin validation, samesite cookies, etc.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:papercut:mobility_print_server:1.0.3512:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3
References () https://fluidattacks.com/advisories/solveig/ - Exploit, Third Party Advisory () https://fluidattacks.com/advisories/solveig/ - Exploit, Third Party Advisory
References () https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-server - Release Notes () https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-server - Release Notes

22 Sep 2023, 18:32

Type Values Removed Values Added
First Time Apple
Papercut mobility Print Server
Papercut
Apple macos
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:papercut:mobility_print_server:1.0.3512:*:*:*:*:*:*:*
CWE CWE-352
References (MISC) https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-server - (MISC) https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-server - Release Notes
References (MISC) https://fluidattacks.com/advisories/solveig/ - (MISC) https://fluidattacks.com/advisories/solveig/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Sep 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-20 16:15

Updated : 2024-11-21 07:58


NVD link : CVE-2023-2508

Mitre link : CVE-2023-2508

CVE.ORG link : CVE-2023-2508


JSON object : View

Products Affected

apple

  • macos

papercut

  • mobility_print_server
CWE
CWE-352

Cross-Site Request Forgery (CSRF)