Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
Solution:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.m-files.com/about/trust-center/security-advisories/cve-2022-3284/ | vendor advisory |
https://product.m-files.com/security-advisories/cve-2022-3284/ | vendor advisory |