First published: Fri Aug 25 2023(Updated: )
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files Classic Web | <23.2 | |
M-Files Classic Web | <23.6.12695.3 | |
M-Files Classic Web | =23.2 |
Update to M-Files release versions 23.6 or newer, or update to LTS versions 23.2 SR3 or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3406 is a Path Traversal vulnerability in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3.
CVE-2023-3406 allows an authenticated user to read some restricted files on the web server.
The severity of CVE-2023-3406 is considered high with a CVSS score of 6.5.
M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 are affected by CVE-2023-3406.
To fix CVE-2023-3406, it is recommended to update M-Files Classic Web to version 23.6.12695.3 or higher, or apply the LTS Service Release Version 23.2 LTS SR3.