First published: Tue Aug 27 2024(Updated: )
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files | <24.2.13421.15 | |
M-Files | <24.8.13981.0 |
Update to patched version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6789 is a medium severity vulnerability that allows authenticated users to exploit a path traversal issue.
To fix CVE-2024-6789, upgrade your M-Files Server to version 24.8.13981.0 or later, or to LTS 24.2.13421.15 SR2 or later.
CVE-2024-6789 affects M-Files Server versions before 24.8.13981.0 and LTS versions before 24.2.13421.15 SR2.
CVE-2024-6789 is classified as a path traversal vulnerability.
CVE-2024-6789 can be exploited by authenticated users of the affected M-Files Server versions.