CVE-2025-2159

Publication date

2025-04-04 06:06:48

Family

M-Files Corporation

State

PUBLISHED

Description

Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local user to run scripts via UI