Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts
References
| Link | Resource |
|---|---|
| https://empower.m-files.com/security-advisories/CVE-2025-3087 | |
| https://product.m-files.com/security-advisories/cve-2025-3087/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-04-04 07:15
Updated : 2026-02-23 11:16
NVD link : CVE-2025-3087
Mitre link : CVE-2025-3087
CVE.ORG link : CVE-2025-3087
JSON object : View
Products Affected
m-files
- m-files_web
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
