First published: Mon Oct 31 2022(Updated: )
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
Credit: vdp@themissinglink.com.au vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files Hubshare | <3.3.10.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39017 is a vulnerability in M-Files Hubshare that allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
CVE-2022-39017 allows authenticated attackers to introduce cross-site scripting attacks through the comments fields in M-Files Hubshare.
CVE-2022-39017 has a severity rating of 8.2 (high).
To fix CVE-2022-39017, update M-Files Hubshare to version 3.3.10.9 or higher.
More information about CVE-2022-39017 can be found at https://www.themissinglink.com.au/security-advisories/cve-2022-39017.