8.2
CVE-2023-5524
- EPSS 0.87%
- Veröffentlicht 20.10.2023 07:15:17
- Zuletzt bearbeitet 23.02.2026 09:16:15
- Quelle security@m-files.com
- CVE-Watchlists
- Unerledigt
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-files ≫ Web Companion SwEditionlts Version < 23.8
M-files ≫ Web Companion SwEdition- Version >= 23.3 < 23.10
M-files ≫ Web Companion Version23.8 Update- SwEditionlts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.87% | 0.749 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.3 | 1.3 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
| security@m-files.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.