CVE-2023-2480
CVSS V2 None
CVSS V3 None
Description
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
Overview
- CVE ID
- CVE-2023-2480
- Assigner
- M-Files Corporation
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-05-25T13:28:29.204Z
- Last Modified Date
- 2023-06-27T12:30:39.116Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2480/ | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-2480 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2480 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 22:09:57 | Added to TrackCVE |