Lucene search

K
cve[email protected]CVE-2022-4270
HistoryDec 02, 2022 - 1:15 p.m.

CVE-2022-4270

2022-12-0213:15:10
CWE-269
web.nvd.nist.gov
27
cve-2022-4270
m-files web
privilege assignment
nvd

2.6 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

4.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.9%

Incorrect privilege assignment issue in M-Files Web in M-Files Web versions beforeΒ 22.5.11436.1 could have changed permissions accidentally.

Affected configurations

NVD
Node
m-filesm-files_serverRange<22.5.11436.1

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "M-Files Web",
    "vendor": "M-Files",
    "versions": [
      {
        "lessThan": "22.5.11436.1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

2.6 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

4.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.9%

Related for CVE-2022-4270