M-Files Server Path Traversal Vulnerability in API Endpoint

Vulnerability

A path traversal vulnerability has been identified in the API endpoint of M-Files Server versions prior to 25.6.14925.0. This vulnerability allows authenticated users to read files on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized file access on the server.

Added: Jun 15, 2025, 8:16 PM
Updated: Jun 15, 2025, 8:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.2
threat
0.0
urgency
1.4
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.