Show filters
93 Total Results
Displaying 11-20 of 93
Sort by:
Attacker Value
Unknown
CVE-2024-6789
Disclosure Date: August 27, 2024 (last updated September 16, 2024)
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
0
Attacker Value
Unknown
CVE-2024-43230
Disclosure Date: August 26, 2024 (last updated September 19, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Shared Files – File Upload Form Shared Files.This issue affects Shared Files: from n/a through 1.7.28.
0
Attacker Value
Unknown
CVE-2024-41258
Disclosure Date: July 31, 2024 (last updated August 16, 2024)
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2024-41256
Disclosure Date: July 31, 2024 (last updated August 16, 2024)
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2024-6881
Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
0
Attacker Value
Unknown
CVE-2024-6124
Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
0
Attacker Value
Unknown
CVE-2024-5142
Disclosure Date: May 24, 2024 (last updated August 27, 2024)
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
0
Attacker Value
Unknown
CVE-2024-4056
Disclosure Date: April 26, 2024 (last updated August 27, 2024)
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
0
Attacker Value
Unknown
CVE-2024-32679
Disclosure Date: April 23, 2024 (last updated April 24, 2024)
Missing Authorization vulnerability in Shared Files PRO Shared Files.This issue affects Shared Files: from n/a through 1.7.16.
0
Attacker Value
Unknown
CVE-2023-4479
Disclosure Date: March 04, 2024 (last updated March 04, 2024)
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
0