Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2025-0648

Disclosure Date: January 23, 2025 (last updated February 17, 2025)
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.
0
Attacker Value
Unknown

CVE-2025-0635

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.
0
Attacker Value
Unknown

CVE-2025-0619

Disclosure Date: January 23, 2025 (last updated January 23, 2025)
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
0
Attacker Value
Unknown

CVE-2024-11176

Disclosure Date: November 20, 2024 (last updated November 20, 2024)
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect calculation of effective permissions.
0
Attacker Value
Unknown

CVE-2024-10127

Disclosure Date: November 20, 2024 (last updated December 16, 2024)
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
0
Attacker Value
Unknown

CVE-2024-10126

Disclosure Date: November 20, 2024 (last updated November 20, 2024)
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
0
Attacker Value
Unknown

CVE-2024-9333

Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
0
Attacker Value
Unknown

CVE-2024-9174

Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
0
Attacker Value
Unknown

CVE-2024-5142

Disclosure Date: May 24, 2024 (last updated August 27, 2024)
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
0
Attacker Value
Unknown

CVE-2024-4056

Disclosure Date: April 26, 2024 (last updated August 27, 2024)
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
0