CVE-2023-2508
Summary
| CVE | CVE-2023-2508 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 16:15:00 UTC |
| Updated | 2023-09-22 18:32:00 UTC |
| Description | The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section). This is possible because the application has no protections against CSRF attacks, like Anti-CSRF tokens, header origin validation, samesite cookies, etc. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | - | All | All | All |
| Application | Papercut | Mobility Print Server | 1.0.3512 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fluidattacks.com/advisories/solveig | MISC | fluidattacks.com | |
| Mobility Print release history | PaperCut | MISC | www.papercut.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.