CVE-2023-4479: Stored XSS Vulnerability in M-Files Web
DESCRIPTION:
Stored XSS Vulnerability in M-Files Web versions before 23.08 allows attacker to execute script on users browser via stored HTML document within limited time period.
AFFECTED PRODUCTS:
M-Files Web before 23.8
MORE INFORMATION:
Exploiting this vulnerability requires access to M-Files Vault to store malicious HTML files and then requires getting a user to open it with specifically provided link. Normally opening the file from the Vault from M-Files Web would not trigger the vulnerability. Time period for successful attempt is also limited.
CVSS 3.1 Base Score: 7.3
CVSS 3.1 Temporal Score: 6.4
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CWE: CWE-79 Cross-Site Scripting
CAPEC: CAPEC-592 Stored XSS
Internal ID: 167872
Date issued: 2023-08-22
EXPLOITABILITY
Publicly disclosed: No
Exploited: No
Probability of exploitation: low - responsibly reported
LINKS
https://www.cve.org/CVERecord?id=CVE-2023-4479
HISTORY
2024-03-04 Published