Vulnerabilities > M Files > M Files WEB > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-01-18 CVE-2021-41807 Improper Restriction of Excessive Authentication Attempts vulnerability in M-Files Server and M-Files web
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
network
low complexity
m-files CWE-307
critical
9.8