216.73.217.22

CVE-2025-13008

· Published 19/12/2025 07:15 · Modified 19/12/2025 18:00

Labels: CVE-2025-13008 2025-12-19CVE-2025-13008[email protected]

Essential information

Published
19/12/2025 07:15
Modified
19/12/2025 18:00
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References