M Files · M-Files Classic Web · CVE-2023-2325
**Name of the Vulnerable Software and Affected Versions**
M-Files Classic Web versions before 23.10
M-Files Classic Web LTS Service Release Versions before 23.2 LTS SR4
M-Files Classic Web LTS Service Release Versions before 23.8 LTS SR1
**Description**
The issue allows an attacker to execute a script on a user's browser via a stored HTML document. This is a Stored XSS vulnerability.
**Recommendations**
For M-Files Classic Web versions before 23.10, update to version 23.10 or later.
For M-Files Classic Web LTS Service Release Versions before 23.2 LTS SR4, update to 23.2 LTS SR4 or later.
For M-Files Classic Web LTS Service Release Versions before 23.8 LTS SR1, update to 23.8 LTS SR1 or later.