Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser

Project Subscriptions

Vendors Products
M-files Subscribe
Hubshare Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-46396 Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
Fixes

Solution

Update to patched version


Workaround

No workaround given by the vendor.

History

Mon, 23 Feb 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared M-files
M-files hubshare
CPEs cpe:2.3:a:m-files:hubshare:*:*:*:*:*:*:*:*
Vendors & Products M-files
M-files hubshare
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Mon, 23 Feb 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
References

Tue, 27 Aug 2024 11:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.3.8 allows authenticated attacker to run scripts in other users browser Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser

Fri, 23 Aug 2024 14:00:00 +0000

Type Values Removed Values Added
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-02-23T10:11:26.951Z

Reserved: 2024-05-20T10:11:41.796Z

Link: CVE-2024-5142

cve-icon Vulnrichment

Updated: 2024-08-01T21:03:10.975Z

cve-icon NVD

Status : Modified

Published: 2024-05-24T06:15:09.360

Modified: 2026-02-23T11:16:17.187

Link: CVE-2024-5142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses