CVE-2023-2480: M-Files
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
Affected products
- M-Files M-Files: before 23.5.12598.0 (fixed in 23.5.12598.0)
Published 2023-05-25. Last modified 2026-06-17.