CVE-2021-37254: High severity m-files vulnerability
Published Oct 28, 2021
·Updated
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
Affected Software
2 affected components
M-Files<20.10.9445.0
M-Files>=20.10.9500.0<20.10.9534.1
Event History
Oct 28, 2021
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-37254.
2
What is the severity of CVE-2021-37254?
The severity of CVE-2021-37254 is high with a CVSS score of 7.5.
3
Which versions of M-Files Web are affected by CVE-2021-37254?
M-Files Web versions before 20.10.9524.1 and 20.10.9445.0 are affected by CVE-2021-37254.
4
What can a remote attacker do with CVE-2021-37254?
A remote attacker could obtain unauthenticated access to 3rd party component license key information on the server.
5
How can I fix CVE-2021-37254?
To fix CVE-2021-37254, it is recommended to update to version 20.10.9524.1 or 20.10.9445.0 of M-Files Web.