Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown
CVE-2022-3284
Disclosure Date: March 06, 2023 (last updated November 08, 2023)
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0.
This issue affects M-Files New Web: before 22.11.12011.0.
0
Attacker Value
Unknown
CVE-2022-4861
Disclosure Date: December 30, 2022 (last updated February 24, 2025)
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
0
Attacker Value
Unknown
CVE-2022-4858
Disclosure Date: December 30, 2022 (last updated February 24, 2025)
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
0
Attacker Value
Unknown
CVE-2022-4264
Disclosure Date: December 09, 2022 (last updated February 24, 2025)
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
0
Attacker Value
Unknown
CVE-2022-4270
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
0
Attacker Value
Unknown
CVE-2022-1911
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
0
Attacker Value
Unknown
CVE-2022-1606
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
0
Attacker Value
Unknown
CVE-2022-21186
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
0
Attacker Value
Unknown
CVE-2022-34187
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
0
Attacker Value
Unknown
CVE-2021-41808
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
0