CVE-2023-2508 describes a Cross-Site Request Forgery (CSRF) vulnerability in PaperCut NG Mobility Print version 1.0.3512, affecting Apple macOS and PaperCut Mobility Print Server products. An unauthenticated attacker can exploit this flaw to trick an instance administrator into configuring client hosts, due to a lack of CSRF protection mechanisms. Rated with a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and requires user interaction, but can lead to high integrity impact by allowing unauthorized configuration changes. There is no confidentiality or availability impact. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.3512CPE matchmatch criteria | cpe:2.3:a:papercut:mobility_print_server:1.0.3512:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.