Vulnerabilities
Vulnerable Software
M-Files:  Security Vulnerabilities
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions beforeĀ 22.5.11436.1 could have changed permissions accidentally.
CVSS Score
2.0
EPSS Score
0.002
Published
2022-12-02
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
CVSS Score
2.4
EPSS Score
0.002
Published
2022-11-30
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-11-30
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
CVSS Score
8.2
EPSS Score
0.003
Published
2022-10-31
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
CVSS Score
8.2
EPSS Score
0.004
Published
2022-10-31
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
CVSS Score
6.3
EPSS Score
0.007
Published
2022-10-31
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
CVSS Score
8.2
EPSS Score
0.006
Published
2022-10-31
Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
CVSS Score
5.2
EPSS Score
0.003
Published
2022-05-02
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
CVSS Score
3.5
EPSS Score
0.001
Published
2022-01-18
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-01-18


Contact Us

Shodan ® - All rights reserved