Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown

CVE-2022-3284

Disclosure Date: March 06, 2023 (last updated November 08, 2023)
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
Attacker Value
Unknown

CVE-2022-4858

Disclosure Date: December 30, 2022 (last updated August 28, 2024)
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
Attacker Value
Unknown

CVE-2022-4270

Disclosure Date: December 02, 2022 (last updated August 28, 2024)
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
Attacker Value
Unknown

CVE-2022-1911

Disclosure Date: November 30, 2022 (last updated August 28, 2024)
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
Attacker Value
Unknown

CVE-2022-1606

Disclosure Date: November 30, 2022 (last updated August 28, 2024)
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
Attacker Value
Unknown

CVE-2021-41808

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
Attacker Value
Unknown

CVE-2021-41809

Disclosure Date: January 17, 2022 (last updated February 23, 2025)
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
Attacker Value
Unknown

CVE-2021-41807

Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.