CVE-2023-4479

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/03/2024
Last modified:
23/02/2026

Description

Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:m-files:m-files:*:*:*:*:*:*:*:* 23.8 (excluding)