Vulnerabilities
Vulnerable Software
M-Files:  >> M-Files Server  Security Vulnerabilities
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
CVSS Score
6.5
EPSS Score
0.007
Published
2024-08-27
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
CVSS Score
7.5
EPSS Score
0.004
Published
2024-04-26
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
CVSS Score
4.3
EPSS Score
0.001
Published
2024-02-23
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-12-20
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-12-20
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-11-28
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.
CVSS Score
5.7
EPSS Score
0.001
Published
2023-11-22
Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-11-22
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
CVSS Score
7.5
EPSS Score
0.002
Published
2023-06-27
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
CVSS Score
3.6
EPSS Score
0.0
Published
2023-04-20


Contact Us

Shodan ® - All rights reserved