CVE-2022-39019: Broken access controls on PDFtron WebviewerUI in M-Files Hubshare
Published Oct 31, 2022
·Updated
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
Affected Software
1 affected component
M-Files Hubshare<3.3.11.3
Event History
Oct 31, 2022
CVE Published
08:09 PM
Data Sourced
08:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-39019?
CVE-2022-39019 is a vulnerability related to broken access controls on PDFtron WebviewerUI in M-Files Hubshare before version 3.3.11.3.
2
What is the severity of CVE-2022-39019?
CVE-2022-39019 has a severity rating of 7.5 (high).
3
How does CVE-2022-39019 affect M-Files Hubshare?
CVE-2022-39019 allows unauthenticated attackers to upload malicious files to the M-Files Hubshare application server.
4
Which version of M-Files Hubshare is affected by CVE-2022-39019?
CVE-2022-39019 affects M-Files Hubshare versions up to but excluding 3.3.11.3.
5
Is there a patch available for CVE-2022-39019?
It is recommended to update M-Files Hubshare to version 3.3.11.3 or newer to mitigate CVE-2022-39019.