Impact
The flaw is a CSS injection vulnerability that permits an authenticated vault administrator to inject arbitrary CSS into the web user interface, thereby altering the visual appearance for all other vault users. It is inferred that this can be leveraged to disguise malicious links, perform UI defacement, or facilitate phishing attempts, thereby eroding user trust. While it does not provide direct code execution or data exfiltration, the attack undermines the integrity of the user interface and it is inferred that it can lead to social engineering attacks.
Affected Systems
M‑Files Web provided by M‑Files Corporation, specifically versions earlier than 26.8.16330.2.
Risk and Exploitability
The CVSS score of 4.8 indicates medium severity. Exploitation requires authenticated access to a vault administrator account, limiting the attacker’s scope to users with that privilege. The EPSS score is 0.00309 (less 1%), indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an organization using the affected M‑Files Web versions should view this as a moderate risk that could compromise the user interface and it is inferred that it could potentially enable phishing attacks.
OpenCVE Enrichment