CVE-2021-41809

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
18/01/2022
Last modified:
26/01/2022

Description

SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*:* 22.1.11017.1 (excluding)