An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
Solution:
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.