Show filters
52 Total Results
Displaying 11-20 of 52
Sort by:
Attacker Value
Unknown
CVE-2024-9891
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the plugin and send a custom reason from the site.
0
Attacker Value
Unknown
CVE-2024-9333
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
0
Attacker Value
Unknown
CVE-2024-9174
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
0
Attacker Value
Unknown
CVE-2024-6789
Disclosure Date: August 27, 2024 (last updated September 16, 2024)
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
0
Attacker Value
Unknown
CVE-2024-4056
Disclosure Date: April 26, 2024 (last updated August 27, 2024)
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
0
Attacker Value
Unknown
CVE-2023-4479
Disclosure Date: March 04, 2024 (last updated March 04, 2024)
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
0
Attacker Value
Unknown
CVE-2024-0563
Disclosure Date: February 23, 2024 (last updated February 23, 2024)
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
0
Attacker Value
Unknown
CVE-2023-6912
Disclosure Date: December 20, 2023 (last updated August 28, 2024)
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
0
Attacker Value
Unknown
CVE-2023-6910
Disclosure Date: December 20, 2023 (last updated January 30, 2024)
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
0
Attacker Value
Unknown
CVE-2023-6239
Disclosure Date: November 28, 2023 (last updated August 28, 2024)
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
0