PT-2022-24674 · M Files+1 · M-Files Hubshare+1

Michael Newton

·

Published

2022-10-31

·

Updated

2023-10-25

·

CVE-2022-39018

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions M-Files Hubshare versions prior to 3.3.11.3
Description The issue concerns broken access controls on PDFtron data, allowing unauthenticated attackers to access restricted PDF files via a known URL.
Recommendations For versions prior to 3.3.11.3, update to version 3.3.11.3 or later to resolve the issue.

Fix

Improper Authentication

Information Disclosure

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-39018

Affected Products

M-Files Hubshare
Pdftron