CVE-2021-41810

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/05/2022
Last modified:
23/02/2026

Description

Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:m-files:server:*:*:*:*:*:*:*:* 22.2.11051.0 (excluding)