Script injection in M-Files Admin
Vulnerability Description
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-41810
Credits & Attribution
No credits recorded in the NVD database.
References
More from M-Files Corporation
View All →Affected Vendor
M-Files Corporation
View all reports →