Vulnerabilities (CVE)

Filtered by vendor M-files Subscribe
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41810 1 M-files 1 Server 2024-02-04 3.5 LOW 4.8 MEDIUM
Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
CVE-2021-37254 1 M-files 1 M-files Web 2024-02-04 5.0 MEDIUM 7.5 HIGH
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
CVE-2021-41808 1 M-files 1 M-files Server 2024-02-04 1.9 LOW 2.3 LOW
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
CVE-2021-41807 1 M-files 2 M-files Server, M-files Web 2024-02-04 5.0 MEDIUM 9.8 CRITICAL
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
CVE-2021-41809 1 M-files 1 M-files Server 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.