CVE-2023-2325 – Stored XSS Vulnerability in M-Files Classic Web
https://notcve.org/view.php?id=CVE-2023-2325
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en las versiones M-Files Classic Web anteriores a 23.10 y LTS Service Release Versions anteriores a 23.2 LTS SR4 y 23.8 LTS SR1 permite al atacante ejecutar scripts en el navegador de los usuarios a través de un documento HTML almacenado. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2325 https://product.m-files.com/security-advisories/cve-2023-2325 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-3406 – Path traversal issue in M-Files Classic Web
https://notcve.org/view.php?id=CVE-2023-3406
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server Un problema de path traversal en las versiones de M-Files Classic Web, el cual afecta a las versiones inferiores a 23.6.12695.3 y a las versiones de lanzamiento del servicio LTS inferiores a 23.2 LTS SR3. Esta vulnerabilidad permite a un usuario autenticado leer algunos archivos restringidos en el servidor web. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-3406 https://product.m-files.com/security-advisories/cve-2023-3406 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2023-3425 – CVE-2023-3425: Out-of-Bounds memory read
https://notcve.org/view.php?id=CVE-2023-3425
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory. Un problema de lectura fuera de los límites en M-Files Server, el cual afecta a las versiones inferiores a 23.8.12892.6 y a las versiones de lanzamiento del servicio LTS inferiores a 23.2 LTS SR3. Esta vulnerabilidad permite a un usuario no autenticado leer una cantidad restringida de bytes de la memoria. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-3425 https://product.m-files.com/security-advisories/cve-2023-3425 • CWE-125: Out-of-bounds Read •