Back

CRITICAL

Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.

Published Jan 18, 2022

Description

Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.

Affected products

Remediation

Vendor solution

Upgrade M-Files to version 21.12.10873.0 or newer.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Jan 18, 2022
Updated Feb 23, 2026
Reserved Sep 29, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner M-Files Corporation
Published Jan 18, 2022
Updated Feb 23, 2026
Exploited since n/a
EUVD-2021-28812