CVE-2024-10126
20.11.2024, 09:15
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.Enginsight
| Vendor | Product | Version |
|---|---|---|
| m-files | m-files_server | 𝑥 < 23.8.12892.6 |
| m-files | m-files_server | 𝑥 < 23.8.12892.23 |
| m-files | m-files_server | 24.2.13421.11 ≤ 𝑥 < 24.2.13421.17 |
| m-files | m-files_server | 24.8.13981.8 ≤ 𝑥 < 24.8.13981.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration