CVE-2023-3406: Path traversal issue in M-Files Classic Web
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-3406?
CVE-2023-3406 is a Path Traversal vulnerability in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3.
How does CVE-2023-3406 impact users?
CVE-2023-3406 allows an authenticated user to read some restricted files on the web server.
What is the severity of CVE-2023-3406?
The severity of CVE-2023-3406 is considered high with a CVSS score of 6.5.
Which software versions are affected by CVE-2023-3406?
M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 are affected by CVE-2023-3406.
How can CVE-2023-3406 be fixed?
To fix CVE-2023-3406, it is recommended to update M-Files Classic Web to version 23.6.12695.3 or higher, or apply the LTS Service Release Version 23.2 LTS SR3.