CVE-2021-41807: Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-41807?
CVE-2021-41807 is a vulnerability in M-Files Server and M-Files Web products that allows unlimited brute-forcing of login accounts due to a lack of rate limiting.
What is the severity of CVE-2021-41807?
The severity of CVE-2021-41807 is critical with a CVSS score of 9.8.
Which versions of M-Files Server and M-Files Web are affected by CVE-2021-41807?
Versions of M-Files Server and M-Files Web before 21.12.10873.0 are affected by CVE-2021-41807.
How does CVE-2021-41807 impact user accounts?
CVE-2021-41807 allows unlimited attempts in certain user accounts, making brute-forcing login accounts easier.
Where can I find more information about CVE-2021-41807?
More information about CVE-2021-41807 can be found at the M-Files Trust Center's security vulnerabilities page.