First published: Fri Oct 20 2023(Updated: )
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
<23.8 | ||
>=23.3<23.10 | ||
=23.8 |
Update to fixed version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5523 is a vulnerability that allows remote code execution due to an execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1.
CVE-2023-5523 has a severity rating of high (8.6).
M-Files Web Companion versions before 23.10 and LTS Service Release Versions before 23.8 LTS SR1 are affected by CVE-2023-5523.
To fix CVE-2023-5523, it is recommended to update M-Files Web Companion to release version 23.10 or LTS Service Release Version 23.8 LTS SR1 or later.
More information about CVE-2023-5523 can be found at the following reference link: [CVE-2023-5523](https://www.m-files.com/about/trust-center/security-advisories/cve-2023-5523/)