Vulnerabilities (CVE)

Filtered by vendor M-files Subscribe
Total 35 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37253 1 M-files 1 M-files Web 2024-04-11 7.8 HIGH 7.5 HIGH
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application
CVE-2023-6912 1 M-files 1 M-files Server 2023-12-28 N/A 9.8 CRITICAL
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
CVE-2023-6910 1 M-files 1 M-files Server 2023-12-28 N/A 6.5 MEDIUM
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
CVE-2023-6189 1 M-files 1 M-files Server 2023-12-10 N/A 5.3 MEDIUM
Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.
CVE-2023-6117 1 M-files 1 M-files Server 2023-12-10 N/A 7.5 HIGH
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.
CVE-2023-6239 1 M-files 1 M-files Server 2023-12-10 N/A 8.8 HIGH
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
CVE-2023-3425 1 M-files 1 Classic Web 2023-12-10 N/A 5.3 MEDIUM
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
CVE-2023-3406 1 M-files 1 Classic Web 2023-12-10 N/A 6.5 MEDIUM
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
CVE-2023-2325 1 M-files 1 Classic Web 2023-12-10 N/A 5.4 MEDIUM
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
CVE-2023-5523 1 M-files 1 Web Companion 2023-12-10 N/A 7.8 HIGH
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution 
CVE-2023-5524 1 M-files 1 Web Companion 2023-12-10 N/A 7.3 HIGH
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
CVE-2023-0213 2 M-files, Microsoft 2 M-files, Windows 2023-12-10 N/A 7.8 HIGH
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
CVE-2023-0382 1 M-files 1 M-files Server 2023-12-10 N/A 6.5 MEDIUM
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
CVE-2023-0384 1 M-files 1 M-files Server 2023-12-10 N/A 7.5 HIGH
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
CVE-2023-2480 1 M-files 1 M-files 2023-12-10 N/A 7.8 HIGH
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
CVE-2023-3405 1 M-files 1 M-files Server 2023-12-10 N/A 7.5 HIGH
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
CVE-2023-0383 1 M-files 1 M-files Server 2023-12-10 N/A 7.5 HIGH
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
CVE-2023-2112 1 M-files 1 M-files Server 2023-12-10 N/A 7.8 HIGH
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. 
CVE-2022-4861 1 M-files 1 M-files Client 2023-12-10 N/A 4.9 MEDIUM
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
CVE-2022-4858 1 M-files 1 M-files Server 2023-12-10 N/A 7.5 HIGH
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.