An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
History

Mon, 16 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 08:45:00 +0000

Type Values Removed Values Added
Description An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
Title Open redirection in M-Files Mobile
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/RE:M/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published: 2025-06-16T08:27:13.170Z

Updated: 2025-06-16T16:33:03.809Z

Reserved: 2025-03-07T11:57:54.664Z

Link: CVE-2025-2091

cve-icon Vulnrichment

Updated: 2025-06-16T16:32:19.819Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T09:15:19.067

Modified: 2025-06-16T12:32:18.840

Link: CVE-2025-2091

cve-icon Redhat

No data.