CVE-2023-3425: M-Files Classic Web

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.

Affected products

  • M-Files Classic Web: before 23.2 (fixed in 23.2); before 23.6.12695.3 (fixed in 23.6.12695.3); version 23.2 only

Published 2023-08-25. Last modified 2026-06-17.