VYPR
High severity8.2NVD Advisory· Published Oct 20, 2023· Updated Jun 17, 2026

CVE-2023-5524

CVE-2023-5524

Description

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows

Remote Code Execution

via specific file types

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Range: <23.10 and <23.8 LTS SR1
  • cpe:2.3:a:m-files:web_companion:*:*:*:*:lts:*:*:*+ 3 more
    • cpe:2.3:a:m-files:web_companion:*:*:*:*:lts:*:*:*range: <23.8
    • cpe:2.3:a:m-files:web_companion:*:*:*:*:-:*:*:*range: >=23.3,<23.10
    • cpe:2.3:a:m-files:web_companion:23.8:-:*:*:lts:*:*:*
    • (no CPE)range: 23.3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.