Lucene search

K
cve[email protected]CVE-2023-4479
HistoryMar 04, 2024 - 8:15 a.m.

CVE-2023-4479

2024-03-0408:15:08
CWE-79
web.nvd.nist.gov
29
cve-2023-4479
stored xss
m-files web
security vulnerability
nvd

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "M-Files Web",
    "vendor": "M-Files Corporation",
    "versions": [
      {
        "lessThan": "23.8.12892.6",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2023-4479