CVE-2023-5524: M-Files Web Companion allows Remote Code Execution for some filetypes
Published Oct 20, 2023
·Updated
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows
Remote Code Execution
via specific file types
Affected Software
3 affected components
M-Files Web Companion<23.8
M-Files Web Companion>=23.3<23.10
M-Files Web Companion=23.8
Remediation
Information
Update to fixed version
Event History
Oct 20, 2023
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
RemedyDescriptionSeverityWeakness
Data Sourced
07:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5524.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1'.
3
What is the severity of CVE-2023-5524?
The severity of CVE-2023-5524 is high with a CVSS score of 8.2.
4
What is the affected software?
The affected software is M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1.
5
How does CVE-2023-5524 allow remote code execution?
CVE-2023-5524 allows remote code execution through specific file types.