CVE-2023-3406

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 25, 2023
Updated: Aug 31, 2023
CWE ID 306

Summary

CVE-2023-3406 is a newly disclosed vulnerability affecting M-Files Classic Web versions prior to 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3. This issue involves a Path Traversal vulnerability, allowing authenticated users to access some restricted files on the web server. By manipulating file paths, attackers could potentially gain unauthorized access to sensitive information, posing a significant risk to data security. It is recommended that affected organizations apply the necessary patches to mitigate this vulnerability promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • VMware vCloud Director

Affected Vendors

  • VMware Inc.