← Vulnerability feed

Vulnerability record · CVE-2023-42954 · published 21 March 2024

CVE-2023-42954: Claris pro execution with unnecessary privileges vulnerability

Claris · Claris Pro

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

4.9 CVSS 3.1 Medium EPSS 0.45% · top 63.6% CWE-250 · Execution with unnecessary privileges
4.9CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-42954 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-46295Claris filemaker server code injection vulnerabilityApache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t…EPSS 1.0%7.8CVE-2023-42920Claris pro uncontrolled search path element vulnerabilityClaris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.EPSS 0.18%7.5CVE-2024-27790Claris filemaker server improper access control vulnerabilityClaris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. Thi…EPSS 0.46%6.1CVE-2025-46320Claris filemaker server cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This…EPSS 0.22%6.1CVE-2024-27794Claris filemaker server cross-site scripting vulnerabilityClaris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled paramete…EPSS 0.31%5.5CVE-2021-44147Claris filemaker pro xml external entity (xxe) vulnerabilityAn XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files …EPSS 1.2%5.4CVE-2025-46296Claris filemaker server improper authorization vulnerabilityAn authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative …EPSS 0.17%5.3CVE-2025-46294Claris filemaker server information exposure vulnerabilityTo enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8do…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2023-42954), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.