Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
Advisories
Source ID Title
EUVD EUVD EUVD-2021-28815 Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 16 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Title Script injection in M-Files Server products with versions before 22.2.11051.0, allows executing stored script in admin tool Script injection in M-Files Server products with versions before 22.2.11051.0, allows executing stored script in admin tool

cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2024-09-16T17:18:03.386Z

Reserved: 2021-09-29T00:00:00

Link: CVE-2021-41810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-02T20:15:08.050

Modified: 2024-11-21T06:26:48.373

Link: CVE-2021-41810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.