A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 15 Jun 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. | |
Title | Path traversal in M-Files API | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: M-Files Corporation
Published: 2025-06-15T19:42:24.617Z
Updated: 2025-06-16T13:46:48.208Z
Reserved: 2025-06-10T07:36:27.344Z
Link: CVE-2025-5964

Updated: 2025-06-16T13:46:23.208Z

Status : Awaiting Analysis
Published: 2025-06-15T20:15:31.037
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-5964

No data.