Show filters
93 Total Results
Displaying 11-20 of 93
Sort by:
Attacker Value
Unknown

CVE-2024-6789

Disclosure Date: August 27, 2024 (last updated September 16, 2024)
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
Attacker Value
Unknown

CVE-2024-43230

Disclosure Date: August 26, 2024 (last updated September 19, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Shared Files – File Upload Form Shared Files.This issue affects Shared Files: from n/a through 1.7.28.
Attacker Value
Unknown

CVE-2024-41258

Disclosure Date: July 31, 2024 (last updated August 16, 2024)
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
Attacker Value
Unknown

CVE-2024-41256

Disclosure Date: July 31, 2024 (last updated August 16, 2024)
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
Attacker Value
Unknown

CVE-2024-6881

Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
Attacker Value
Unknown

CVE-2024-6124

Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
Attacker Value
Unknown

CVE-2024-5142

Disclosure Date: May 24, 2024 (last updated August 27, 2024)
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
0
Attacker Value
Unknown

CVE-2024-4056

Disclosure Date: April 26, 2024 (last updated August 27, 2024)
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
0
Attacker Value
Unknown

CVE-2024-32679

Disclosure Date: April 23, 2024 (last updated April 24, 2024)
Missing Authorization vulnerability in Shared Files PRO Shared Files.This issue affects Shared Files: from n/a through 1.7.16.
0
Attacker Value
Unknown

CVE-2023-4479

Disclosure Date: March 04, 2024 (last updated March 04, 2024)
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
0