Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28812 | Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier. |
Fixes
Solution
Upgrade M-Files to version 21.12.10873.0 or newer.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Feb 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: M-Files Corporation
Published:
Updated: 2026-02-23T07:49:22.819Z
Reserved: 2021-09-29T00:00:00
Link: CVE-2021-41807
No data.
Status : Modified
Published: 2022-01-18T17:15:08.837
Modified: 2026-02-23T08:16:10.610
Link: CVE-2021-41807
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD