CVE-2024-9333

MEDIUM

M-Files Connector for Copilot <24.9.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation

Scores

CVSS v4 5.3
EPSS 0.0003
EPSS Percentile 9.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-281
Status published
Products (1)
M-Files Corporation/M-Files Connector for Copilot < 24.9.3
Published Oct 02, 2024
Tracked Since Feb 18, 2026