First published: Fri Apr 04 2025(Updated: )
Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files | >=25.1.14445.5<=25.2.14524.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3087 is classified as a high severity vulnerability.
To fix CVE-2025-3087, you should upgrade M-Files Web to a version later than 25.2.14524.4.
CVE-2025-3087 affects authenticated users of M-Files Web versions from 25.1.14445.5 to 25.2.14524.4.
CVE-2025-3087 is a Stored Cross-Site Scripting (XSS) vulnerability.
Yes, CVE-2025-3087 can potentially lead to data breaches due to unauthorized script execution.