CVE-2022-39016: Javascript injection in PDFtron in M-Files Hubshare
Published Oct 31, 2022
·Updated
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
Affected Software
1 affected component
M-Files Hubshare<3.3.10.9
Event History
Oct 31, 2022
CVE Published
08:06 PM
Data Sourced
08:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-39016?
CVE-2022-39016 is a vulnerability that allows authenticated attackers to perform an account takeover through a crafted PDF upload in M-Files Hubshare before version 3.3.10.9.
2
How severe is CVE-2022-39016?
CVE-2022-39016 has a severity rating of 8.8 (high).
3
How does CVE-2022-39016 affect M-Files Hubshare?
CVE-2022-39016 affects M-Files Hubshare before version 3.3.10.9.
4
How can an attacker exploit CVE-2022-39016?
An attacker can exploit CVE-2022-39016 by uploading a crafted PDF file.
5
Is there a fix for CVE-2022-39016?
Yes, updating M-Files Hubshare to version 3.3.10.9 or later will fix CVE-2022-39016.