First published: Tue Jan 18 2022(Updated: )
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <21.12.10873.0 | |
M-files M-files Web | <21.12.10873.0 |
Upgrade M-Files to version 21.12.10873.0 or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41807 is a vulnerability in M-Files Server and M-Files Web products that allows unlimited brute-forcing of login accounts due to a lack of rate limiting.
The severity of CVE-2021-41807 is critical with a CVSS score of 9.8.
Versions of M-Files Server and M-Files Web before 21.12.10873.0 are affected by CVE-2021-41807.
CVE-2021-41807 allows unlimited attempts in certain user accounts, making brute-forcing login accounts easier.
More information about CVE-2021-41807 can be found at the M-Files Trust Center's security vulnerabilities page.