First published: Tue Jun 27 2023(Updated: )
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <23.6.12695.3 |
Update to patched version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3405 is a vulnerability in M-Files Server that allows an anonymous user to cause a denial of service.
The severity of CVE-2023-3405 is high, with a severity score of 7.5
Versions of M-Files Server before 23.6.12695.3 (excluding 23.2 SR2 and newer) are affected by CVE-2023-3405.
An anonymous user can exploit CVE-2023-3405 by providing an unchecked parameter value, leading to a denial of service.
Yes, upgrading to version 23.6.12695.3 or newer of M-Files Server will fix the CVE-2023-3405 vulnerability.