CVE-2025-5964
15.06.2025, 20:15
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
| Vendor | Product | Version | 
|---|---|---|
| m-files | m-files_server | 𝑥 < 24.8.13981.16 | 
| m-files | m-files_server | 25.2.14524.3 ≤ 𝑥 < 25.2.14524.9 | 
| m-files | m-files_server | 25.3.14681.7 ≤ 𝑥 < 25.6.14925.0 | 
𝑥
= Vulnerable software versions