First published: Mon Oct 31 2022(Updated: )
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
Credit: vdp@themissinglink.com.au vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files Hubshare | <3.3.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39018 is a vulnerability that refers to broken access controls on PDFtron data in M-Files Hubshare before version 3.3.11.3.
CVE-2022-39018 has a severity rating of 8.2 (high).
Unauthenticated attackers can exploit CVE-2022-39018 by accessing restricted PDF files through a known URL.
M-Files Hubshare versions up to and excluding 3.3.11.3 are affected by CVE-2022-39018.
To fix CVE-2022-39018, it is recommended to update M-Files Hubshare to version 3.3.11.3 or later.