Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: M-Files Corporation
Published: 2022-01-18T16:51:50.929Z
Updated: 2026-02-23T07:49:22.819Z
Reserved: 2021-09-29T00:00:00.000Z
Link: CVE-2021-41807
No data.
Status : Modified
Published: 2022-01-18T17:15:08.837
Modified: 2026-02-23T08:16:10.610
Link: CVE-2021-41807
No data.
ReportizFlow