CVE-2023-2533

HIGH(8.4)KEVElevated Risk

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.

KEV Information

Vendor
PaperCut
Product
NG/MF
Date Added
July 28, 2025
Due Date
August 18, 2025
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.7
Impact Score
6.0

CWEs

Affected Products

VendorProductVersion
papercutpapercut mf< 20.1.8; >= 21.0.0, < 21.2.12; >= 22.0.0, < 22.1.1
papercutpapercut ng< 20.1.8; >= 21.0.0, < 21.2.12; >= 22.0.0, <= 22.1.1

Multiple CVSS Assessments

Source: [email protected](Secondary)
8.4
HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

CVSS Score

8.4
HIGH(8.4)

EPSS Score

EPSS Score29.25%
EPSS Percentile98.0%

Dates

PublishedJune 20, 2023
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.