Record summary

CVE-2023-2533 has a selected CVSS score of 8.4 (high). CISA lists CVE-2023-2533 in KEV.

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jul 28, 2025 · CISA
VulnCheck KEV
Listed · Jul 28, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unaffected

CVE List22.0.10 to < 2.1.1affected
21.2.12unaffected
20.1.8unaffected

References

5