CVE Database
/

CVE-2025-13008

Back to search

CVE-2025-13008

Published: Dec 19, 2025

Modified: Feb 23, 2026

PUBLISHED

Description

An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.

VendorProductVersions

M-Files Corporation

M-Files Server

affected
0 - < 25.12.15491.7
unaffected
25.8.15085.18
unaffected
25.2.14524.14
unaffected
24.8.13981.17

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now