Show filters
52 Total Results
Displaying 11-20 of 52
Sort by:
Attacker Value
Unknown
CVE-2024-6124
Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
0
Attacker Value
Unknown
CVE-2024-5142
Disclosure Date: May 24, 2024 (last updated August 27, 2024)
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
0
Attacker Value
Unknown
CVE-2024-4056
Disclosure Date: April 26, 2024 (last updated August 27, 2024)
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
0
Attacker Value
Unknown
CVE-2023-4479
Disclosure Date: March 04, 2024 (last updated March 04, 2024)
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
0
Attacker Value
Unknown
CVE-2024-0563
Disclosure Date: February 23, 2024 (last updated February 23, 2024)
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
0
Attacker Value
Unknown
CVE-2023-6912
Disclosure Date: December 20, 2023 (last updated August 28, 2024)
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
0
Attacker Value
Unknown
CVE-2023-6910
Disclosure Date: December 20, 2023 (last updated January 30, 2024)
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
0
Attacker Value
Unknown
CVE-2023-6239
Disclosure Date: November 28, 2023 (last updated August 28, 2024)
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
0
Attacker Value
Unknown
CVE-2023-6189
Disclosure Date: November 22, 2023 (last updated August 28, 2024)
Missing access permissions checks
in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export
jobs using the M-Files API methods.
0
Attacker Value
Unknown
CVE-2023-6117
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server
before 23.11.13156.0 which allows attackers to execute DoS attacks.
0