Back to Database
Status published
Medium
CVE-2022-39019
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare
Vulnerability Description
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-39019
Credits & Attribution
No credits recorded in the NVD database.
More from M-Files
View All →CVE-2023-6239
Incorrect calculation of effective permissions
Medium
5.4
CVE-2023-6189
Improper Permission Handling in M-Files Server
Medium
4.3
CVE-2023-6117
M-Files REST API allows Denial of Service
Medium
5.7
CVE-2023-5524
M-Files Web Companion allows Remote Code Execution for some filetypes
High
8.2
CVE-2023-5523
M-Files Web Companion allows Remote Code Execution
High
8.6
Affected Vendor
M-Files
View all reports →Affected Software
Hubshare
Vulnerable Versions:
3.3.1.6
Timeline
Official Publish:
October 31st, 2022
Last Modified:
May 2nd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
MITRE ATT&CK TTPs
T1190
Exploit Public-Facing Application
Initial Access
T1078
Valid Accounts
Persistence
T1556
Modify Authentication Process
Credential Access
T1505.003
Web Shell
Persistence
T1105
Ingress Tool Transfer
Command and Control
T1059
Command and Scripting Interpreter
Execution
T1565.002
Stored Data Manipulation
Impact