PT-2025-3985 · M Files · M-Files Server

Published

2025-01-23

·

Updated

2025-10-03

·

CVE-2025-0619

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 25.1
Description The issue allows a highly privileged user to recover external connector passwords due to unsafe password recovery from the configuration.
Recommendations For versions prior to 25.1, update to version 25.1 or later to resolve the issue.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-0619

Affected Products

M-Files Server