CVE-2023-2325
M-Files Online vulnerability analysis and mitigation

Overview

A stored Cross-Site Scripting (XSS) vulnerability was identified in M-Files Classic Web, tracked as CVE-2023-2325. The vulnerability affects M-Files Server versions before 23.10, 23.2 LTS SR4, and 23.8 LTS SR1. This security issue was discovered by Thomas Riedmaier and Abian Blome from Siemens Energy and was responsibly reported to M-Files (M-Files Advisory).

Technical details

The vulnerability allows an attacker to execute malicious scripts in users' browsers through stored HTML documents. The CVSS 3.1 Base Score is 7.3, with a Temporal Score of 6.6 (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:R). The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') and falls under CAPEC-592 Stored XSS attack pattern (M-Files Advisory).

Impact

If successfully exploited, the vulnerability could allow attackers to execute arbitrary scripts in the context of users' browsers, potentially leading to unauthorized access to sensitive information or manipulation of web content. However, exploitation requires specific conditions to be met, including access to the M-Files Vault to store malicious HTML files and user interaction through specifically crafted links (M-Files Advisory).

Exploitability

The vulnerability has not been publicly disclosed or exploited in the wild. The probability of exploitation is considered low due to responsible reporting and the specific conditions required for successful exploitation. An attacker would need access to M-Files Vault and would have to convince a user to open a malicious file through a specifically provided link, such as via email. Normal file access through M-Files Web would not trigger the vulnerability (M-Files Advisory).

Mitigation and workarounds

Users are advised to upgrade to M-Files Server version 23.10 or later, or apply the appropriate service releases: 23.2 LTS SR4 or 23.8 LTS SR1, which contain fixes for this vulnerability (M-Files Advisory).

Additional resources


SourceThis report was generated using AI

Related M-Files Online vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-4479MEDIUM5.4
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files
NoYesMar 04, 2024
CVE-2023-2325MEDIUM5.4
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:classic_web
NoYesOct 20, 2023
CVE-2026-18371MEDIUM5.1
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesAug 19, 2026
CVE-2025-3087MEDIUM5.1
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesApr 04, 2025
CVE-2026-18372MEDIUM4.8
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management