CSRF in PaperCut Mobility Print leads to sophisticated phishing
5,3
Medium
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
CSRF in PaperCut Mobility Print leads to sophisticated phishing
Code name
State
Public
Release date
20 sept 2023
Affected product
PaperCut Mobility Print
Affected version(s)
Version 1.0.3512
Vulnerability name
Cross-site request forgery
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v3.1 base score
5.3
Exploit available
Yes
CVE ID(s)
Description
The PaperCut Mobility Print
version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section). This is possible because the application has no protections against CSRF attacks, like Anti-CSRF tokens, header origin validation, samesite cookies, etc.
Vulnerability
This vulnerability occurs because the application has no protections against CSRF attacks, like Anti-CSRF tokens, header origin validation, samesite cookies, etc.
Exploitation
In this scenario an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section).
Then, when the administrator wants to share the link to users so that they can configure their credentials, they are actually sending users to a malicious website that pretends to be the PaperCut NG login, with the goal of exfiltrating the credentials.
exploit.html
Our security policy
We have reserved the ID CVE-2023-2508 to refer to this issue from now on. Disclosure policy
System Information
Version: PaperCut Mobility Print 1.0.3512
Operating System: MacOS
Mitigation
An updated version of PaperCut Mobility Print is available at the vendor page.
References
Vendor page https://www.papercut.com/
PaperCut Mobility Print server release history https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-server
PaperCut Mobility Print android app release history https://www.papercut.com/help/manuals/mobility-print/release-history/#mobility-print-android-app
Timeline
IA generativa
3 may 2023
Vendor Confirmed Vuln.
8 may 2023
Vulnerability patched
22 ago 2023
Vendor contacted
3 may 2023
Vendor replied
3 may 2023
Public disclosure
20 sept 2023