Vulnerability CVE-2023-2508


Published: 2023-09-20

Description:
The `PaperCutNG Mobility Print` version 1.0.3512 application allows an

unauthenticated attacker to perform a CSRF attack on an instance

administrator to configure the clients host (in the "configure printer

discovery" section). This is possible because the application has no

protections against CSRF attacks, like Anti-CSRF tokens, header origin

validation, samesite cookies, etc.



 References:
https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-server
https://fluidattacks.com/advisories/solveig/

Copyright 2026, cxsecurity.com

 

Back to Top