CVE-2023-6239

MEDIUM

M-Files Server <23.11.13168.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.

Scores

CVSS v3 5.4
EPSS 0.0006
EPSS Percentile 17.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-281
Status published
Products (3)
m-files/m-files_server 23.9
m-files/m-files_server 23.10
m-files/m-files_server 23.11 - 23.11.13168.7
Published Nov 28, 2023
Tracked Since Feb 18, 2026