Description
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
Affected products
M-Files Web before 23.8
More information
Exploiting this vulnerability requires access to M-Files Vault to store malicious HTML files and then requires getting a user to open it with specifically provided link. Normally opening the file from the Vault from M-Files Web would not trigger the vulnerability. Time period for successful attempt is also limited. CVSS 3.1 Base Score: 7.3 CVSS 3.1 Temporal Score: 6.4 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N CWE: CWE-79 Cross-Site Scripting CAPEC: CAPEC-592 Stored XSS Internal ID: 167872
Exploitability
Publicly disclosed: No Exploited: No Probability of exploitation: low – responsibly reported
