Executive brief
PaperCut NG and MF are print management solutions used by organizations to manage and secure printing environments. A security flaw allows an attacker to trick a logged-in administrator into performing unintended actions by clicking a malicious link. This could lead to unauthorized changes in security settings or the execution of malicious code, potentially compromising the entire printing infrastructure and sensitive data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in PaperCut NG/MF. The vulnerability is triggered when an authenticated administrator with an active session is deceived into interacting with a specially crafted malicious link or web page. Because the application fails to properly validate that requests are intentional and originate from the user, the attacker can perform actions with the administrator's privileges. This can result in the modification of critical security configurations or remote code execution. The vulnerability has been observed in active exploitation according to CISA. Patches are available in versions 20.1.8, 21.2.12, and 22.1.1.
Affected products
- PaperCut PaperCut MF up to (excluding) 20.1.8, 21.0.0 up to (excluding) 21.2.12, 22.0.0 up to (excluding) 22.1.1
- PaperCut PaperCut NG up to (excluding) 20.1.8, 21.0.0 up to (excluding) 21.2.12, 22.0.0 up to (excluding) 22.1.1
Timeline
- 2023-06-01: advisory: Vendor security bulletin published
- 2025-07-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog