ZeroHour

CVE-2023-2533

KEV PoC large

CSRF Flaw in PaperCut NG/MF Enables Security Changes and Arbitrary Code Execution

CISA: PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

CVSS 3.1
8.8 high
EPSS
29%p98
Published
()
KEV added
AI analysis

CVE-2023-2533 is a cross-site request forgery (CSRF, CWE-352) flaw in PaperCut's NG and MF print-management software, where state-changing requests submitted through the product's web console are not adequately verified as originating from a trusted source. An attacker triggers it by persuading an authenticated PaperCut administrator or user to follow attacker-controlled content, such as a crafted link, while their web session is active. Under specific conditions, the attacker can then alter security settings or execute arbitrary code in the context of the victim's session. Any organization running PaperCut NG or MF is potentially affected, though the available data does not specify exact affected or fixed version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-28, confirming active exploitation; no public proof-of-concept is known and CVSS is not yet scored, but EPSS puts the probability of exploitation within 30 days at 29.2% (98th percentile).

What to do: Apply PaperCut's mitigations per the vendor's security advisory, including upgrading NG and MF to the fixed release specified there, and audit recent security-setting changes for signs of tampering; federal users must follow applicable BOD 22-01 guidance (including for cloud services) or discontinue use if mitigations are unavailable. Since CSRF requires an active authenticated session, restrict admin-console access and treat phishing links aimed at PaperCut administrators as a live vector.

Affected
PaperCut NG/MF
Estimated exposure
largetens of thousands to ~100,000 organizations running PaperCut NG/MF (vendor cites 100k+ deployments), with only a subset of instances internet-exposed — PaperCut NG/MF is a leading print-management platform heavily deployed in education and enterprise, implying an installed base in the tens of thousands of sites, while public scan-based reporting during the 2023 PaperCut exploitation wave…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes.

CISA Known Exploited Vulnerability
Affected
PaperCut NG/MF
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
papercut
Products
papercut mf, papercut ng
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news