Vulnerabilities (CVE)

Filtered by vendor M-files Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6910 1 M-files 1 M-files Server 2023-12-28 N/A 6.5 MEDIUM
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
CVE-2023-6189 1 M-files 1 M-files Server 2023-11-30 N/A 5.3 MEDIUM
Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.
CVE-2021-41810 1 M-files 1 Server 2022-05-10 3.5 LOW 4.8 MEDIUM
Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
CVE-2021-41809 1 M-files 1 M-files Server 2022-01-26 4.0 MEDIUM 4.3 MEDIUM
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.