PT-2023-15884 · M Files · M-Files Web+1
CVE-2022-4862
·
Publicado
2023-03-06
·
Atualizado
2026-02-23
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
M-Files Web versions prior to 22.12.12140.3
M-Files New Web versions prior to 22.12.12140.3
Description
The issue allows rendering of HTML provided by another authenticated user in the browser, which can lead to the theft of user sensitive information.
Recommendations
For M-Files Web versions prior to 22.12.12140.3, update to version 22.12.12140.3 or later.
For M-Files New Web versions prior to 22.12.12140.3, update to version 22.12.12140.3 or later.
Correção
Information Disclosure
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
M-Files New Web
M-Files Web