CVE

CVE-2023-2508

CVE-2023-2508

The `PaperCutNG Mobility Print` version 1.0.3512 application allows an

unauthenticated attacker to perform a CSRF attack on an instance

administrator to configure the clients host (in the "configure printer

discovery" section). This is possible because the application has no

protections against CSRF attacks, like Anti-CSRF tokens, header origin

validation, samesite cookies, etc.

Source: CVE-2023-2508

Exit mobile version