CVE-2022-39018: Broken access controls on PDFtron data in M-Files Hubshare
Published Oct 31, 2022
·Updated
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
Affected Software
1 affected component
M-Files Hubshare<3.3.11.3
Event History
Oct 31, 2022
CVE Published
08:09 PM
Data Sourced
08:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-39018?
CVE-2022-39018 is a vulnerability that refers to broken access controls on PDFtron data in M-Files Hubshare before version 3.3.11.3.
2
What is the severity of CVE-2022-39018?
CVE-2022-39018 has a severity rating of 8.2 (high).
3
How can unauthenticated attackers exploit CVE-2022-39018?
Unauthenticated attackers can exploit CVE-2022-39018 by accessing restricted PDF files through a known URL.
4
Which software is affected by CVE-2022-39018?
M-Files Hubshare versions up to and excluding 3.3.11.3 are affected by CVE-2022-39018.
5
Is there a fix available for CVE-2022-39018?
To fix CVE-2022-39018, it is recommended to update M-Files Hubshare to version 3.3.11.3 or later.