CVE Vulnerabilities

CVE-2023-6189

Published: Nov 22, 2023 | Modified: Nov 30, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Missing access permissions checks

in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export

jobs using the M-Files API methods.

Affected Software

Name Vendor Start Version End Version
M-files_server M-files * 23.11.13156.0 (excluding)

References

  • https://https://www.m-files.com/about/trust-center/security-advisories/cve-2023-6189/