CVE-2023-2325 is a stored Cross-Site Scripting (XSS) vulnerability affecting M-Files Classic Web versions prior to 23.10, and LTS Service Release versions before 23.2 LTS SR4 and 23.8 LTS SR1. An authenticated attacker can exploit this by embedding malicious scripts within stored HTML documents, which then execute in a user's browser. Rated as Medium severity (CVSS 5.4), this vulnerability requires low privileges and user interaction, with a low impact on confidentiality and integrity. The attack vector is network-based, and its complexity is low. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion or media coverage, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.10CPE matchmatch criteria | cpe:2.3:a:m-files:classic_web:*:*:*:*:-:*:*:* | ||
23.2CPE matchmatch criteria | cpe:2.3:a:m-files:classic_web:23.2:-:*:*:lts:*:*:* | ||
23.8CPE matchmatch criteria | cpe:2.3:a:m-files:classic_web:23.8:-:*:*:lts:*:*:* | ||
>= 0, < 23.10CPE match | cpe:2.3:a:m-files:m-files_web:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.