Vulnerabilities > CVE-2023-6239 - Improper Preservation of Permissions vulnerability in M-Files Server 23.10/23.9

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
m-files
CWE-281

Summary

Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.

Vulnerable Configurations

Part Description Count
Application
M-Files
3

Common Weakness Enumeration (CWE)