CVE-2025-2159

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 653

Summary

CVE-2025-2159 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows. This issue allows authenticated local users to execute scripts through the user interface, posing a significant security risk. Successful exploitation could lead to unintended actions, such as data theft or unauthorized system modifications. Users are strongly advised to upgrade to the latest version of the M-Files Server Admin tool to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks