Show filters
52 Total Results
Displaying 1-10 of 52
Sort by:
Attacker Value
Unknown
CVE-2025-0648
Disclosure Date: January 23, 2025 (last updated February 17, 2025)
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.
0
Attacker Value
Unknown
CVE-2025-0635
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Denial of service condition in M-Files Server in versions before
25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.
0
Attacker Value
Unknown
CVE-2025-0619
Disclosure Date: January 23, 2025 (last updated January 23, 2025)
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
0
Attacker Value
Unknown
CVE-2024-11176
Disclosure Date: November 20, 2024 (last updated November 20, 2024)
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect calculation of effective permissions.
0
Attacker Value
Unknown
CVE-2024-10127
Disclosure Date: November 20, 2024 (last updated December 16, 2024)
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
0
Attacker Value
Unknown
CVE-2024-10126
Disclosure Date: November 20, 2024 (last updated November 20, 2024)
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
0
Attacker Value
Unknown
CVE-2024-9333
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
0
Attacker Value
Unknown
CVE-2024-9174
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
0
Attacker Value
Unknown
CVE-2024-6789
Disclosure Date: August 27, 2024 (last updated September 16, 2024)
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
0
Attacker Value
Unknown
CVE-2024-6881
Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
0