An information disclosure vulnerability in M-Files Server...
High severity
Unreviewed
Published
Dec 19, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Dec 19, 2025
Published to the GitHub Advisory Database
Dec 19, 2025
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
References