Description
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
Published: 2023-10-20
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to fixed version

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-33827 Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
References

Wed, 28 Aug 2024 20:30:00 +0000


Wed, 28 Aug 2024 09:30:00 +0000


Wed, 28 Aug 2024 09:00:00 +0000

Type Values Removed Values Added
Description Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document. Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
References

Subscriptions

M-files Classic Web
cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-02-23T08:40:56.290Z

Reserved: 2023-04-27T08:15:36.501Z

Link: CVE-2023-2325

cve-icon Vulnrichment

Updated: 2024-08-02T06:19:14.651Z

cve-icon NVD

Status : Modified

Published: 2023-10-20T07:15:15.213

Modified: 2026-02-23T09:16:14.443

Link: CVE-2023-2325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses