Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
References
Configurations
History
No history.
Information
Published : 2022-05-02 20:15
Updated : 2026-02-23 12:16
NVD link : CVE-2021-41810
Mitre link : CVE-2021-41810
CVE.ORG link : CVE-2021-41810
JSON object : View
Products Affected
m-files
- server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
