Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
Solution:
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.m-files.com/about/trust-center/security-advisories/cve-2022-1606/ | vendor advisory |
https://product.m-files.com/security-advisories/cve-2022-1606/ | vendor advisory |