CVE-2024-10126: Local file inclusion vulnerability in M-Files Server
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10126?
CVE-2024-10126 has a medium severity rating due to its potential for local file exposure to authenticated users.
How do I fix CVE-2024-10126?
To mitigate CVE-2024-10126, upgrade M-Files Server to version 24.11 or apply relevant security patches as indicated.
Which versions of M-Files Server are vulnerable to CVE-2024-10126?
CVE-2024-10126 affects M-Files Server versions prior to 24.11, excluding 24.8 SR1, 24.2 SR3, and 23.8 SR7.
Can an unauthenticated user exploit CVE-2024-10126?
No, CVE-2024-10126 requires the attacker to be an authenticated user to exploit the local file inclusion vulnerability.
What types of files can be accessed through CVE-2024-10126?
CVE-2024-10126 allows access to a limited set of local file types via document preview.