Vulnerabilities
Vulnerable Software
M-Files:  >> M-Files Server  Security Vulnerabilities
User-controlled operations could have allowed Denial of Service in M-Files ServerĀ before 23.4.12528.1 due to uncontrolled memory consumption.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-04-05
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-03-06
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.
CVSS Score
5.0
EPSS Score
0.003
Published
2023-03-06
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
CVSS Score
4.4
EPSS Score
0.001
Published
2022-12-30
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions beforeĀ 22.5.11436.1 could have changed permissions accidentally.
CVSS Score
2.0
EPSS Score
0.001
Published
2022-12-02
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
CVSS Score
2.4
EPSS Score
0.001
Published
2022-11-30
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-11-30
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
CVSS Score
3.5
EPSS Score
0.001
Published
2022-01-18
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-01-18
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
CVSS Score
2.0
EPSS Score
0.0
Published
2022-01-18


Contact Us

Shodan ® - All rights reserved