First published: Thu Oct 28 2021(Updated: )
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Web | <20.10.9445.0 | |
M-files M-files Web | >=20.10.9500.0<20.10.9534.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-37254.
The severity of CVE-2021-37254 is high with a CVSS score of 7.5.
M-Files Web versions before 20.10.9524.1 and 20.10.9445.0 are affected by CVE-2021-37254.
A remote attacker could obtain unauthenticated access to 3rd party component license key information on the server.
To fix CVE-2021-37254, it is recommended to update to version 20.10.9524.1 or 20.10.9445.0 of M-Files Web.