PT-2022-11489 · M Files · M-Files Server

Published

2022-01-18

·

Updated

2026-02-23

·

CVE-2021-41809

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 22.1.11017.1
Description The issue concerns a Server-Side Request Forgery (SSRF) vulnerability. It is related to a preview function in M-Files Server products that allows making queries from the server with certain document types referencing external entities.
Recommendations For versions prior to 22.1.11017.1, update to version 22.1.11017.1 or later to resolve the issue. As a temporary workaround, consider restricting the preview function to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2021-41809

Affected Products

M-Files Server