Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
References
Configurations
History
28 Aug 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
27 Jun 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications |
02 Jun 2023, 18:34
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
First Time |
M-files
M-files m-files |
|
CWE | CWE-862 | |
References |
|
|
References | (MISC) https://https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2480/ - Broken Link | |
CPE | cpe:2.3:a:m-files:m-files:*:*:*:*:*:*:*:* |
Information
Published : 2023-05-25 14:15
Updated : 2024-08-28 09:15
NVD link : CVE-2023-2480
Mitre link : CVE-2023-2480
CVE.ORG link : CVE-2023-2480
JSON object : View
Products Affected
m-files
- m-files