Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor M-files Subscribe
Total 18 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3284 1 M-files 1 M-files Server 2023-03-10 N/A 7.5 HIGH
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
CVE-2022-4862 1 M-files 1 M-files Server 2023-03-10 N/A 7.6 HIGH
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.
CVE-2022-4858 1 M-files 1 M-files Server 2023-01-06 N/A 7.5 HIGH
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
CVE-2022-4861 1 M-files 1 M-files Client 2023-01-06 N/A 4.9 MEDIUM
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
CVE-2022-4264 1 M-files 1 M-files 2022-12-12 N/A 4.3 MEDIUM
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
CVE-2022-4270 1 M-files 1 M-files Server 2022-12-05 N/A 2.6 LOW
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
CVE-2022-1911 1 M-files 1 M-files Server 2022-12-02 N/A 5.3 MEDIUM
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
CVE-2022-1606 1 M-files 1 M-files Server 2022-12-02 N/A 4.3 MEDIUM
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
CVE-2022-39016 1 M-files 1 Hubshare 2022-11-01 N/A 8.8 HIGH
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
CVE-2022-39017 1 M-files 1 Hubshare 2022-11-01 N/A 5.4 MEDIUM
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
CVE-2022-39018 1 M-files 1 Hubshare 2022-11-01 N/A 7.5 HIGH
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
CVE-2022-39019 1 M-files 1 Hubshare 2022-11-01 N/A 7.5 HIGH
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
CVE-2021-37254 1 M-files 1 M-files Web 2022-07-12 5.0 MEDIUM 7.5 HIGH
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
CVE-2021-41810 1 M-files 1 Server 2022-05-10 3.5 LOW 4.8 MEDIUM
Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
CVE-2021-37253 1 M-files 1 M-files Web 2022-03-31 7.8 HIGH 7.5 HIGH
** DISPUTED ** M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application.
CVE-2021-41809 1 M-files 1 M-files Server 2022-01-25 4.0 MEDIUM 4.3 MEDIUM
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
CVE-2021-41808 1 M-files 1 M-files Server 2022-01-25 1.9 LOW 2.3 LOW
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
CVE-2021-41807 1 M-files 2 M-files Server, M-files Web 2022-01-25 5.0 MEDIUM 9.8 CRITICAL
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.