CVE detail
CVE-2023-2325 — CVE-2023-2325
Published 2023-10-20 · Modified 2026-06-17 · Vendor m-files · Product classic_web · Source nvd
HIGH
severity
CVSS-derived band
0.0043
EPSS probability
exploitation probability, 30d
35.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References