← Back

CVE-2021-41810

nvd nist
Published: May 2, 2022Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable

Affected (1)

Products: M Files: Server
1 product
Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 22.2.11051.0

Timeline

No history available yet.