Back to search
CVE-2025-13008
Published: Dec 19, 2025
Modified: Feb 23, 2026
PUBLISHED
Description
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
| Vendor | Product | Versions |
|---|---|---|
M-Files Corporation | M-Files Server | affected 0 - < 25.12.15491.7unaffected 25.8.15085.18unaffected 25.2.14524.14unaffected 24.8.13981.17 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now