Vulnerabilities > M Files

DATE CVE VULNERABILITY TITLE RISK
2023-10-20 CVE-2023-2325 Cross-site Scripting vulnerability in M-Files Classic web 23.2/23.6.12695.3/23.8
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
network
low complexity
m-files CWE-79
5.4
2023-10-20 CVE-2023-5523 Inclusion of Functionality from Untrusted Control Sphere vulnerability in M-Files web Companion 23.8
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
local
low complexity
m-files CWE-829
7.8
2023-10-20 CVE-2023-5524 Unrestricted Upload of File with Dangerous Type vulnerability in M-Files web Companion 23.8
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
local
low complexity
m-files CWE-434
7.3
2023-08-25 CVE-2023-3406 Path Traversal vulnerability in M-Files Classic web 23.2
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
network
low complexity
m-files CWE-22
6.5
2023-08-25 CVE-2023-3425 Out-of-bounds Read vulnerability in M-Files Classic web 23.2
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
network
low complexity
m-files CWE-125
5.3
2023-06-27 CVE-2023-3405 Unspecified vulnerability in M-Files Server
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
network
low complexity
m-files
7.5
2023-05-25 CVE-2023-2480 Missing Authorization vulnerability in M-Files
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
local
low complexity
m-files CWE-862
7.8
2023-04-20 CVE-2023-0383 Resource Exhaustion vulnerability in M-Files Server
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
network
low complexity
m-files CWE-400
7.5
2023-04-20 CVE-2023-0384 Resource Exhaustion vulnerability in M-Files Server
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
network
low complexity
m-files CWE-400
7.5
2023-04-20 CVE-2023-2112 Unspecified vulnerability in M-Files Server
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
local
low complexity
m-files
7.8