CVE-2025-13008

HIGH

M-Files Server <25.12.15491.7, 25.8, 25.2, 24.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.

Scores

CVSS v4 8.6
EPSS 0.0003
EPSS Percentile 7.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-359
Status published
Products (4)
M-Files Corporation/M-Files Server < 25.12.15491.7
M-Files Corporation/M-Files Server 24.8.13981.17
M-Files Corporation/M-Files Server 25.2.14524.14
M-Files Corporation/M-Files Server 25.8.15085.18
Published Dec 19, 2025
Tracked Since Feb 18, 2026