Vulnerabilities
Vulnerable Software
M-Files:  Security Vulnerabilities
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.
CVSS Score
5.9
EPSS Score
0.001
Published
2025-01-23
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
CVSS Score
4.6
EPSS Score
0.001
Published
2025-01-23
Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.
CVSS Score
6.3
EPSS Score
0.001
Published
2025-01-23
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
CVSS Score
9.2
EPSS Score
0.001
Published
2024-11-20
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-11-20
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
CVSS Score
6.9
EPSS Score
0.011
Published
2024-10-02
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
CVSS Score
8.4
EPSS Score
0.009
Published
2024-08-27
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
CVSS Score
8.5
EPSS Score
0.003
Published
2024-07-29
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
CVSS Score
8.5
EPSS Score
0.001
Published
2024-07-29
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
CVSS Score
7.0
EPSS Score
0.011
Published
2024-05-24


Contact Us

Shodan ® - All rights reserved