Description
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows

Remote Code Execution

via specific file types
Published: 2023-10-20
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update to fixed version

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-57837 Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
History

Mon, 23 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
References

Wed, 28 Aug 2024 19:30:00 +0000


Wed, 28 Aug 2024 09:45:00 +0000


Wed, 28 Aug 2024 08:30:00 +0000

Type Values Removed Values Added
Description Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
References

Subscriptions

M-files Web Companion
cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-02-23T08:54:53.666Z

Reserved: 2023-10-11T13:31:23.607Z

Link: CVE-2023-5524

cve-icon Vulnrichment

Updated: 2024-08-02T07:59:44.751Z

cve-icon NVD

Status : Modified

Published: 2023-10-20T07:15:17.717

Modified: 2026-02-23T09:16:15.753

Link: CVE-2023-5524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses