8.6
CVE-2023-5523
- EPSS 0.56%
- Veröffentlicht 20.10.2023 07:15:17
- Zuletzt bearbeitet 23.02.2026 09:16:15
- Quelle security@m-files.com
- CVE-Watchlists
- Unerledigt
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-files ≫ Web Companion SwEditionlts Version < 23.8
M-files ≫ Web Companion SwEdition- Version >= 23.3 < 23.10
M-files ≫ Web Companion Version23.8 Update- SwEditionlts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.679 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| security@m-files.com | 8.6 | 1.8 | 6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.