First published: Mon Oct 31 2022(Updated: )
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
Credit: vdp@themissinglink.com.au vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files Hubshare | <3.3.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39019 is a vulnerability related to broken access controls on PDFtron WebviewerUI in M-Files Hubshare before version 3.3.11.3.
CVE-2022-39019 has a severity rating of 7.5 (high).
CVE-2022-39019 allows unauthenticated attackers to upload malicious files to the M-Files Hubshare application server.
CVE-2022-39019 affects M-Files Hubshare versions up to but excluding 3.3.11.3.
It is recommended to update M-Files Hubshare to version 3.3.11.3 or newer to mitigate CVE-2022-39019.