An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
M-files
M-files m-files Mobile |
|
| CPEs | cpe:2.3:a:m-files:m-files_mobile:*:*:*:*:*:android:*:* cpe:2.3:a:m-files:m-files_mobile:*:*:*:*:*:iphone_os:*:* |
|
| Vendors & Products |
M-files
M-files m-files Mobile |
|
| Metrics |
cvssV3_1
|
Mon, 16 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs. | |
| Title | Open redirection in M-Files Mobile | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: M-Files Corporation
Published: 2025-06-16T08:27:13.170Z
Updated: 2025-06-16T16:33:03.809Z
Reserved: 2025-03-07T11:57:54.664Z
Link: CVE-2025-2091
Updated: 2025-06-16T16:32:19.819Z
Status : Analyzed
Published: 2025-06-16T09:15:19.067
Modified: 2025-10-29T18:58:21.523
Link: CVE-2025-2091
No data.