
CVE-2023-3405 – Denial of service condition in M-Files Server
https://notcve.org/view.php?id=CVE-2023-3405
27 Jun 2023 — Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-3405 • CWE-248: Uncaught Exception •

CVE-2023-2480 – Elevation of Privilege in M-Files Desktop Client
https://notcve.org/view.php?id=CVE-2023-2480
25 May 2023 — Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications • https://https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2480 • CWE-280: Improper Handling of Insufficient Permissions or Privileges CWE-862: Missing Authorization •

CVE-2023-2112 – Desktop component allows lateral movement between sessions
https://notcve.org/view.php?id=CVE-2023-2112
20 Apr 2023 — Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2112 • CWE-284: Improper Access Control •

CVE-2023-0384 – Uncontrolled Resource Consuption in M-Files Server
https://notcve.org/view.php?id=CVE-2023-0384
20 Apr 2023 — User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0384 • CWE-400: Uncontrolled Resource Consumption •

CVE-2023-0383 – Uncontrolled Resource Consuption in M-Files Server
https://notcve.org/view.php?id=CVE-2023-0383
20 Apr 2023 — User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0383 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2023-0382 – Uncontrolled Resource Consumption in M-Files Server
https://notcve.org/view.php?id=CVE-2023-0382
05 Apr 2023 — User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0382 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2023-0213 – Local Elevation of Privilege in M-Files
https://notcve.org/view.php?id=CVE-2023-0213
29 Mar 2023 — Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking. • https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0213 • CWE-427: Uncontrolled Search Path Element •

CVE-2022-4862 – XSS vulnerability in M-Files Web
https://notcve.org/view.php?id=CVE-2022-4862
06 Mar 2023 — Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4862 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-3284 – Insecure way of passing a download key
https://notcve.org/view.php?id=CVE-2022-3284
06 Mar 2023 — Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0. Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-3284 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-4861 – Incorrect Implementation of Authentication Algorithm
https://notcve.org/view.php?id=CVE-2022-4861
30 Dec 2022 — Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource. La implementación incorrecta en el protocolo de autenticación en M-Files Client anterior a 22.5.11356.0 permite a usuarios con altos privilegios obtener tokens de otros usuarios para otro recurso. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4861 • CWE-287: Improper Authentication CWE-303: Incorrect Implementation of Authentication Algorithm •