Loading HuntDB...

Version 0

SINGLE_NUMBER 10 CVEs

Known Vulnerabilities

CVE-2023-6189

Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.

MEDIUM CVSS 4.3 Published Nov 22, 2023

CVE-2023-6117

A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.

MEDIUM CVSS 5.7 Published Nov 22, 2023

CVE-2023-3425

Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.

MEDIUM CVSS 6.5 Published Aug 25, 2023

CVE-2023-3405

Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service

HIGH CVSS 7.5 Published Jun 27, 2023

CVE-2023-0384

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.

MEDIUM CVSS 6.5 Published Apr 20, 2023

CVE-2023-0383

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

HIGH CVSS 7.5 Published Apr 20, 2023

CVE-2023-0382

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

MEDIUM CVSS 6.5 Published Apr 05, 2023

CVE-2022-4858

Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.

MEDIUM CVSS 4.4 Published Dec 30, 2022

CVE-2022-1911

Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.

MEDIUM CVSS 5.3 Published Nov 30, 2022

CVE-2022-1606

Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.

LOW CVSS 2.4 Published Nov 30, 2022