Search
Welcome to M-Files Empower – our new support experience. We'd love to hear what you think!Give feedback
Home/Product information and downloads/Security advisories

CVE-2023-4479 Stored XSS Vulnerability in M-Files Web

2024-03-04

Description

Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.

Affected products

M-Files Web before 23.8

More information

Exploiting this vulnerability requires access to M-Files Vault to store malicious HTML files and then requires getting a user to open it with specifically provided link. Normally opening the file from the Vault from M-Files Web would not trigger the vulnerability. Time period for successful attempt is also limited. CVSS 3.1 Base Score: 7.3 CVSS 3.1 Temporal Score: 6.4 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N CWE: CWE-79 Cross-Site Scripting CAPEC: CAPEC-592 Stored XSS Internal ID: 167872

Exploitability

Publicly disclosed: No Exploited: No Probability of exploitation: low – responsibly reported