Back to Database
Status published
High
CVE-2022-39018
Broken access controls on PDFtron data in M-Files Hubshare
Vulnerability Description
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-39018
Credits & Attribution
No credits recorded in the NVD database.
More from M-Files
View All →CVE-2023-6239
Incorrect calculation of effective permissions
Medium
5.4
CVE-2023-6189
Improper Permission Handling in M-Files Server
Medium
4.3
CVE-2023-6117
M-Files REST API allows Denial of Service
Medium
5.7
CVE-2023-5524
M-Files Web Companion allows Remote Code Execution for some filetypes
High
8.2
CVE-2023-5523
M-Files Web Companion allows Remote Code Execution
High
8.6
Affected Vendor
M-Files
View all reports →Affected Software
Hubshare
Vulnerable Versions:
3.3.1.6
Timeline
Official Publish:
October 31st, 2022
Last Modified:
May 2nd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
MITRE ATT&CK TTPs
T1213
Data from Information Repositories
Collection
T1005
Data from Local System
Collection
T1552
Unsecured Credentials
Credential Access
T1041
Exfiltration Over C2 Channel
Exfiltration
T1190
Exploit Public-Facing Application
Initial Access
T1078
Valid Accounts
Persistence
T1021
Remote Services
Lateral Movement
T1098
Account Manipulation
Privilege Escalation
T1556
Modify Authentication Process
Credential Access