Classic Web
Vendor:
First CVE: Aug 25, 2023 · Active for 2 years
3
Total CVEs
More Total CVEs than 64% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Classic Web over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2023
2 years ago
Most Recent CVE
Oct 20, 2023
1,010 days ago
CVE Severity & Scoring
Classic Web3 CVEs
100%
All CVEs352,719 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (66.7%)
Unknown0 (0.0%)
Required1 (33.3%)
Privileges Required
Low2 (66.7%)
High0 (0.0%)
None1 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3425MEDIUM Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of | Aug 25, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-3406MEDIUM Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files | Aug 25, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-2325MEDIUM Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on user | Oct 20, 2023 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (3 CVEs).
Media Mentions
Signals from CVEs in this product scope (3 CVEs).
Top CNAs Publishing CVEs For Classic Web
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 23.8 | 1 | 5.4 | 0.4% | 0 | 0 |
| 23.2 | 3 | 5.7 | 0.5% | 0 | 0 |