CVE-2025-5964
MEDIUMM-Files Server < 24.8.13981.16 and 25.3.14681.7-25.6.14925.0 - Authenticated Path Traversal via API Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-5964. PoCs published by byteReaper77.
AI-analyzed exploit summary This repository contains a Proof-of-Concept (PoC) in C for a suspected Path Traversal vulnerability in M-Files version 25.6.14925.0. The PoC attempts to read sensitive files by injecting traversal payloads into REST API endpoints.
Description
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
Exploits (1)
This repository contains a Proof-of-Concept (PoC) in C for a suspected Path Traversal vulnerability in M-Files version 25.6.14925.0. The PoC attempts to read sensitive files by injecting traversal payloads into REST API endpoints.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N