Back

HIGH

Path traversal in M-Files API

Published Aug 27, 2024

Description

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files

Affected products

Remediation

Vendor solution

Update to patched version

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Aug 27, 2024
Updated Feb 23, 2026
Reserved Jul 16, 2024
CISA Vulnrichment
Updated Aug 27, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner M-Files Corporation
Published Aug 27, 2024
Updated Feb 23, 2026
Exploited since n/a
EUVD-2024-47819