CVE-2023-5524

HIGH

M-files Web Companion < 23.8 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types

Scores

CVSS v3 8.2
EPSS 0.0087
EPSS Percentile 75.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (3)
m-files/web_companion 23.8
m-files/web_companion < 23.8
m-files/web_companion 23.3 - 23.10
Published Oct 20, 2023
Tracked Since Feb 18, 2026