CVE-2025-3087: Stored XSS Vulnerability in M-Files Web
Published Apr 4, 2025
·Updated
Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts
Affected Software
2 affected components
M-Files M-Files Web>=25.1.14445.5<=25.2.14524.4
M-Files M-Files Web>=25.1.14445.5<=25.2.14524.4
Event History
Apr 4, 2025
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3087?
CVE-2025-3087 is classified as a high severity vulnerability.
2
How do I fix CVE-2025-3087?
To fix CVE-2025-3087, you should upgrade M-Files Web to a version later than 25.2.14524.4.
3
Who is affected by CVE-2025-3087?
CVE-2025-3087 affects authenticated users of M-Files Web versions from 25.1.14445.5 to 25.2.14524.4.
4
What type of vulnerability is CVE-2025-3087?
CVE-2025-3087 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2025-3087 lead to data breaches?
Yes, CVE-2025-3087 can potentially lead to data breaches due to unauthorized script execution.