CVE-2023-3406: M-Files Classic Web
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
Affected products
- M-Files Classic Web: before 23.2 (fixed in 23.2); before 23.6.12695.3 (fixed in 23.6.12695.3); version 23.2 only
Published 2023-08-25. Last modified 2026-06-17.