Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
References

Wed, 28 Aug 2024 19:30:00 +0000


Wed, 28 Aug 2024 09:45:00 +0000


Wed, 28 Aug 2024 08:45:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published: 2023-05-25T13:28:29.204Z

Updated: 2026-02-23T08:42:43.815Z

Reserved: 2023-05-02T13:56:42.382Z

Link: CVE-2023-2480

cve-icon Vulnrichment

Updated: 2024-08-02T06:26:09.083Z

cve-icon NVD

Status : Modified

Published: 2023-05-25T14:15:10.120

Modified: 2026-02-23T09:16:14.633

Link: CVE-2023-2480

cve-icon Redhat

No data.