PT-2022-28144 · M Files · M-Files Server

Published

2022-12-30

·

Updated

2026-02-23

·

CVE-2022-4858

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 22.10.11846.0
Description The issue allows sensitive information to be inserted into log files, potentially enabling the obtainment of sensitive tokens from logs if specific configurations are set.
Recommendations For versions prior to 22.10.11846.0, update to version 22.10.11846.0 or later to resolve the issue.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2022-4858

Affected Products

M-Files Server