Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
Solution:
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4861/ | broken link |
https://product.m-files.com/security-advisories/cve-2022-4861/ | vendor advisory |