Medium severity4.3NVD Advisory· Published Nov 20, 2024· Updated Jun 17, 2026
CVE-2024-10126
CVE-2024-10126
Description
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
40+ 3 more
- (no CPE)range: 0
- (no CPE)range: <24.11, excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7
- cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:*range: <23.8.12892.6
- cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:*range: <23.8.12892.23
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.