CVE-2023-42954

MEDIUM

FileMaker Server <20.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

Scores

CVSS v3 4.9
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Products (2)
claris/claris_pro
claris/filemaker_server < 20.3.1
Published Mar 21, 2024
Tracked Since Feb 18, 2026