CVE-2022-4264: Incorrect privilege assignment

DESCRIPTION

Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

AFFECTED PRODUCTS

M-Files Web Classic version before 22.8.11691.0.

MORE INFORMATION

Low privilege user could have changed some limited local web configuration data affecting M-Files Web.

CVSS 3.1 Score: 6.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CWE: CWE-269 Improper Privilege Management
CAPEC: CAPEC-176 Configuration/Environment Manipulation

Internal ID: 163836

Date issued: 2022-12-09

LINKS

https://www.cve.org/CVERecord?id=CVE-2022-4264

Review M-Files on Gartner® Peer Insights™ & get a $25 gift card!

X