A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Claris Filemaker_Server
cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*
|
— |
21.1.7
|
|
Claris Filemaker_Server
cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*
|
22.0.1
|
22.0.4
|