Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
References
Configurations
History
21 Nov 2024, 07:58
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
28 Aug 2024, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
27 Jun 2023, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications |
02 Jun 2023, 18:34
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | (MISC) https://https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2480/ - Broken Link | |
| CWE | CWE-862 | |
| CPE | cpe:2.3:a:m-files:m-files:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
25 May 2023, 15:58
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-05-25 14:15
Updated : 2024-11-21 07:58
NVD link : CVE-2023-2480
Mitre link : CVE-2023-2480
CVE.ORG link : CVE-2023-2480
JSON object : View
Products Affected
m-files
- m-files
