First published: Mon Oct 31 2022(Updated: )
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
Credit: vdp@themissinglink.com.au vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files Hubshare | <3.3.10.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39016 is a vulnerability that allows authenticated attackers to perform an account takeover through a crafted PDF upload in M-Files Hubshare before version 3.3.10.9.
CVE-2022-39016 has a severity rating of 8.8 (high).
CVE-2022-39016 affects M-Files Hubshare before version 3.3.10.9.
An attacker can exploit CVE-2022-39016 by uploading a crafted PDF file.
Yes, updating M-Files Hubshare to version 3.3.10.9 or later will fix CVE-2022-39016.