PT-2022-26509 · M Files · M-Files Web

Published

2022-12-02

·

Updated

2026-02-23

·

CVE-2022-4270

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions M-Files Web versions before 22.5.11436.1
Description The issue is related to an incorrect privilege assignment in M-Files Web, which could have resulted in accidental changes to permissions.
Recommendations For M-Files Web versions before 22.5.11436.1, update to version 22.5.11436.1 or later to resolve the issue.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-4270

Affected Products

M-Files Web