
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-2480 is a security vulnerability affecting M-Files Client versions prior to 23.5.12598.0 (excluding 23.2 SR2 and newer). The vulnerability was disclosed on May 25, 2023, and involves missing access permissions checks that could allow elevation of privilege through UI extension applications (M-Files Advisory).
The vulnerability has been assigned a CVSS 3.1 score of 7.5 with the vector CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N. It is categorized under CWE-280 (Improper Handling of Insufficient Permissions or Privileges). The technical nature of the vulnerability relates to insufficient permission checks in the M-Files Client's UI extension applications functionality (M-Files Advisory).
The vulnerability could lead to elevation of privilege, potentially allowing attackers to gain higher levels of access than intended. The CVSS scoring indicates high potential impact on confidentiality and integrity, though availability is not affected (M-Files Advisory).
The vulnerability has been patched in M-Files Client version 23.5.12598.0. Users are advised to upgrade to this version or newer to mitigate the vulnerability. The fix is also included in versions 23.2 SR2 and newer (M-Files Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."