M-Files Server
cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*
- < 26.3.15818.5
A blind server-side request forgery (SSRF) vulnerability has been identified in M-Files Server versions prior to 26.3.15818.5. This vulnerability exists in the legacy connection methods of the document co-authoring features, allowing an unauthenticated attacker to manipulate the server into sending HTTP GET requests to arbitrary URLs. While the exploitation of this vulnerability can reveal the IP address of the M-Files Server handling the request, no other sensitive information is included in the GET request. Additionally, successful exploitation can cause a moderate performance impact on the M-Files Server instance.
Exploitation of this vulnerability can lead to blind server-side request forgery, allowing an attacker to make the server send requests to internal or external resources, potentially leading to further exploitation or information disclosure.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.