M-Files Server
cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*
- < 25.12.15491.7
- < 25.8 LTS SR3
- < 25.2 LTS SR3
- < 24.8 LTS SR5
A vulnerability allowing information disclosure has been identified in M-Files Server versions prior to 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3, and 24.8 LTS SR5. This vulnerability allows an authenticated attacker using M-Files Web to capture session tokens from other active users. The attacker could then impersonate these users and perform actions using their identity and permissions.
Exploitation of this vulnerability allows an authenticated attacker to capture and reuse session tokens of other users, enabling impersonation and unauthorized actions on behalf of those users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.