PT-2024-16799 · M Files · M-Files Aino

Published

2024-11-20

·

Updated

2024-11-20

·

CVE-2024-11176

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions M-Files Aino versions prior to 24.10
Description The issue is related to improper access control, allowing an authenticated user to access object information due to an incorrect calculation of effective permissions.
Recommendations For versions prior to 24.10, update to version 24.10 or later to resolve the issue.

Fix

Incorrect Authorization

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-11176

Affected Products

M-Files Aino