Show filters
52 Total Results
Displaying 21-30 of 52
Sort by:
Attacker Value
Unknown

CVE-2023-5524

Disclosure Date: October 20, 2023 (last updated August 28, 2024)
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
Attacker Value
Unknown

CVE-2023-5523

Disclosure Date: October 20, 2023 (last updated August 28, 2024)
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
Attacker Value
Unknown

CVE-2023-2325

Disclosure Date: October 20, 2023 (last updated August 28, 2024)
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
Attacker Value
Unknown

CVE-2023-3425

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
Attacker Value
Unknown

CVE-2023-3406

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
Attacker Value
Unknown

CVE-2023-3405

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
Attacker Value
Unknown

CVE-2023-2480

Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
Attacker Value
Unknown

CVE-2023-2112

Disclosure Date: April 20, 2023 (last updated August 28, 2024)
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
Attacker Value
Unknown

CVE-2023-0384

Disclosure Date: April 20, 2023 (last updated August 28, 2024)
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
Attacker Value
Unknown

CVE-2023-0383

Disclosure Date: April 20, 2023 (last updated August 28, 2024)
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.