Back

HIGH

Insecure way of passing a download key

Published Mar 6, 2023

Description

Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.

Affected products

Remediation

Vendor solution

Upgrade to patched version of M-Files.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Mar 6, 2023
Updated Feb 23, 2026
Reserved Sep 23, 2022
CISA Vulnrichment
Updated Aug 28, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner M-Files Corporation
Published Mar 6, 2023
Updated Feb 23, 2026
Exploited since n/a
EUVD-2022-42680