PT-2024-37400 · M Files · M-Files Hubshare

Emma Kantanen

+1

·

Published

2024-07-29

·

Updated

2026-02-23

·

CVE-2024-6124

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/RE:M/U:Clear
Name of the Vulnerable Software and Affected Versions: M-Files Hubshare versions prior to 5.0.6.0
Description: The issue allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. This is achieved through a reflected XSS attack.
Recommendations: For versions prior to 5.0.6.0, update to version 5.0.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6124

Affected Products

M-Files Hubshare