Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 Aug 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 Aug 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: M-Files Corporation
Published: 2023-05-25T13:28:29.204Z
Updated: 2026-02-23T08:42:43.815Z
Reserved: 2023-05-02T13:56:42.382Z
Link: CVE-2023-2480
Updated: 2024-08-02T06:26:09.083Z
Status : Modified
Published: 2023-05-25T14:15:10.120
Modified: 2026-02-23T09:16:14.633
Link: CVE-2023-2480
No data.
ReportizFlow