CVE-2025-2091: Open redirection in M-Files Mobile
An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2091?
CVE-2025-2091 is considered a medium severity vulnerability due to its potential for exploitation via maliciously crafted PDF files.
How do I fix CVE-2025-2091?
To mitigate CVE-2025-2091, update the M-Files mobile applications for Android and iOS to version 25.6.0 or later.
What are the risks associated with CVE-2025-2091?
The risks of CVE-2025-2091 include the potential for attackers to redirect users to untrusted URLs, leading to phishing or other harmful activities.
Who is affected by CVE-2025-2091?
CVE-2025-2091 affects users of M-Files Mobile applications on Android and iOS prior to version 25.6.0.
What is an open redirection vulnerability as seen in CVE-2025-2091?
An open redirection vulnerability, such as CVE-2025-2091, occurs when an application allows the redirection of a URL to an untrusted site, potentially leading users to malicious content.