CVE-2023-3406

HIGH

M-Files Classic Web < 23.6.12695.3 and < 23.2 LTS SR3 - Authenticated Path Traversal

Title source: llm
STIX 2.1

Description

Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server

Scores

CVSS v3 7.7
EPSS 0.0060
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (3)
m-files/classic_web 23.2
m-files/classic_web < 23.2
m-files/classic_web < 23.6.12695.3
Published Aug 25, 2023
Tracked Since Feb 18, 2026