PT-2023-15884 · M Files · M-Files Web+1

CVE-2022-4862

·

Publicado

2023-03-06

·

Atualizado

2026-02-23

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions M-Files Web versions prior to 22.12.12140.3 M-Files New Web versions prior to 22.12.12140.3
Description The issue allows rendering of HTML provided by another authenticated user in the browser, which can lead to the theft of user sensitive information.
Recommendations For M-Files Web versions prior to 22.12.12140.3, update to version 22.12.12140.3 or later. For M-Files New Web versions prior to 22.12.12140.3, update to version 22.12.12140.3 or later.

Correção

Information Disclosure

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-4862

Produtos afetados

M-Files New Web
M-Files Web