CVE-2023-42954
A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42954?
CVE-2023-42954 is classified as a privilege escalation vulnerability that may expose sensitive information.
How do I fix CVE-2023-42954?
To fix CVE-2023-42954, update to FileMaker Server version 20.3.1 or later.
What software is affected by CVE-2023-42954?
CVE-2023-42954 affects Claris Pro and FileMaker Server versions prior to 20.3.1.
What kind of information could be exposed due to CVE-2023-42954?
CVE-2023-42954 could potentially expose sensitive information to front-end websites when accessing the Admin Console.
Is there a workaround for CVE-2023-42954?
No official workaround is provided for CVE-2023-42954; the best course of action is to perform the software update.