Information Disclosure in M-Files Server Affects User Sessions
CVE-2025-13008
8.6HIGH
What is CVE-2025-13008?
An information disclosure vulnerability exists in M-Files Server that allows authenticated users to exploit the system via M-Files Web. By capturing session tokens of other active users, an attacker can gain unauthorized access and potentially manipulate sensitive data. It is crucial for organizations using affected versions of M-Files Server to update their systems promptly to safeguard against this security risk.
Affected Version(s)
M-Files Server 0 < 25.12.15491.7
M-Files Server 25.8.15085.18
M-Files Server 25.2.14524.14
