CVE-2021-41810 MEDIUM

CVE-2021-41810: Script injection in M-Files Admin

Vendor M-Files Corporation
Product M-Files Server
Weakness CWE-79 · XSS
Published May 2, 2022
Last update February 23, 2026

CVSS base score

5.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable

Key dates

02Disclosure timeline

May 2, 2022 CVE published
February 23, 2026 Record updated