CVE-2024-6789

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/08/2024
Last modified:
16/09/2024

Description

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:* 24.2.13421.15 (excluding)
cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:* 24.8.13981.0 (excluding)


References to Advisories, Solutions, and Tools