CVE-2021-41810
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
02/05/2022
Last modified:
23/02/2026
Description
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
Impact
Base Score 3.x
5.20
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:m-files:server:*:*:*:*:*:*:*:* | 22.2.11051.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



