{"id":"CVE-2023-2533","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-2533","summary":"A Cross-Site Request Forgery (CSRF) vulnerability has been identified in\nPaperCut NG/MF, which, under specific conditions, could potentially enable\nan attacker to alter security settings…","details":"A Cross-Site Request Forgery (CSRF) vulnerability has been identified in\nPaperCut NG/MF, which, under specific conditions, could potentially enable\nan attacker to alter security settings or execute arbitrary code. This could\nbe exploited if the target is an admin with a current login session. Exploiting\nthis would typically involve the possibility of deceiving an admin into clicking\na specially crafted malicious link, potentially leading to unauthorized changes.","published":"2023-06-20T14:45:14.102Z","modified":"2025-10-21T23:05:45.534Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"},"epss":{"score":0.29246,"percentile":0.98026,"asOf":"2026-08-22"},"cisaKev":{"dateAdded":"2025-07-28","dueDate":"2025-08-18","knownRansomwareCampaignUse":false},"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://fluidattacks.com/advisories/arcangel/"},{"type":"WEB","url":"https://www.papercut.com/kb/Main/SecurityBulletinJune2023"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2533"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:05:45.534Z"}}