Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows

Remote Code Execution

Project Subscriptions

Vendors Products
M-files Subscribe
Web Companion Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-57836 Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
Fixes

Solution

Update to fixed version


Workaround

No workaround given by the vendor.

History

Mon, 23 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
References

Wed, 28 Aug 2024 19:30:00 +0000


Wed, 28 Aug 2024 09:45:00 +0000


Wed, 28 Aug 2024 08:45:00 +0000

Type Values Removed Values Added
Description Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution  Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-02-23T08:53:41.857Z

Reserved: 2023-10-11T13:17:44.566Z

Link: CVE-2023-5523

cve-icon Vulnrichment

Updated: 2024-08-02T07:59:44.699Z

cve-icon NVD

Status : Modified

Published: 2023-10-20T07:15:17.650

Modified: 2026-02-23T09:16:15.573

Link: CVE-2023-5523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses