CVE-2022-4862: XSS vulnerability in M-Files Web
Published Mar 6, 2023
·Updated
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information.
This issue affects M-Files New Web: before 22.12.12140.3.
Affected Software
1 affected component
M-Files M-Files server<22.12.12140.3
Remediation
Information
Upgrade to patched version of M-Files.
Event History
Mar 6, 2023
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4862?
CVE-2022-4862 is a vulnerability that allows the rendering of HTML provided by another authenticated user in the browser on M-Files Web before version 22.12.12140.3.
2
How does CVE-2022-4862 impact M-Files Web?
CVE-2022-4862 allows the content to steal user sensitive information on M-Files Web before version 22.12.12140.3.
3
What software versions are affected by CVE-2022-4862?
CVE-2022-4862 affects M-Files New Web before version 22.12.12140.3.
4
How severe is CVE-2022-4862?
CVE-2022-4862 has a severity rating of 7.6 (high).
5
Is there a fix available for CVE-2022-4862?
Yes, upgrading to M-Files Web version 22.12.12140.3 or above will fix CVE-2022-4862.