Show filters
52 Total Results
Displaying 41-50 of 52
Sort by:
Attacker Value
Unknown
CVE-2022-39016
Disclosure Date: October 31, 2022 (last updated October 26, 2023)
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
0
Attacker Value
Unknown
CVE-2022-39017
Disclosure Date: October 31, 2022 (last updated October 26, 2023)
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
0
Attacker Value
Unknown
CVE-2022-39019
Disclosure Date: October 31, 2022 (last updated October 26, 2023)
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
0
Attacker Value
Unknown
CVE-2022-39018
Disclosure Date: October 31, 2022 (last updated October 26, 2023)
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
0
Attacker Value
Unknown
CVE-2021-41810
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
0
Attacker Value
Unknown
CVE-2021-41808
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
0
Attacker Value
Unknown
CVE-2021-41809
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
0
Attacker Value
Unknown
CVE-2021-41807
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
0
Attacker Value
Unknown
CVE-2021-37253
Disclosure Date: December 05, 2021 (last updated February 23, 2025)
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application
0
Attacker Value
Unknown
CVE-2021-37254
Disclosure Date: October 28, 2021 (last updated November 28, 2024)
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
0