{"id":9509,"date":"2025-12-27T10:03:39","date_gmt":"2025-12-27T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/27\/m-files-vulnerability-let-attacker-capture-session-tokens-of-other-active-users\/"},"modified":"2025-12-27T10:03:39","modified_gmt":"2025-12-27T10:03:39","slug":"m-files-vulnerability-let-attacker-capture-session-tokens-of-other-active-users","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/27\/m-files-vulnerability-let-attacker-capture-session-tokens-of-other-active-users\/","title":{"rendered":"M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users"},"content":{"rendered":"<p>    M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An information disclosure vulnerability in M-Files Server enables authenticated attackers to capture and reuse <a href=\"https:\/\/cybersecuritynews.com\/beware-of-blackplague-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">session tokens<\/a> from active users. Potentially gaining unauthorized access to sensitive document management systems.<\/p>\n<p>The flaw, tracked as CVE-2025-13008, affects multiple versions across different release branches and carries a high-severity CVSS 4.0 base score of 8.6.<\/p>\n<p>The vulnerability exists within M-Files Web and requires the attacker to have legitimate authentication credentials.<\/p>\n<p>Once authenticated, an attacker can intercept session tokens of other actively connected users while they perform specific client operations.<\/p>\n<p>By obtaining these tokens, <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-are-hiring-insiders-in-banks-telecoms\/\" target=\"_blank\" rel=\"noreferrer noopener\">threat actors<\/a> can impersonate legitimate users and execute actions in their name and with their permissions.<\/p>\n<p>Including accessing confidential documents and potentially modifying critical information.<\/p>\n<p>The flaw is classified as <a href=\"https:\/\/cybersecuritynews.com\/angular-http-client-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CWE-359<\/a> (Exposure of Private Personal Information to an Unauthorized Actor). It represents a session replay scenario per CAPEC-60.<\/p>\n<p>The attack requires user interaction and network accessibility, making it a practical threat in connected environments.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-affected-versions\"><strong>Affected Versions<\/strong><\/h2>\n<p>Organizations running the following M-Files Server versions are vulnerable and should prioritize patching:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Release Branch<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Vulnerable Versions<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Patched Version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Current Release<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Before 25.12.15491.7<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">25.12.15491.7<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">LTS 25.8<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Before SR3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">25.8.15085.18 (SR3)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">LTS 25.2<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Before SR3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">25.2.14524.14 (SR3)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">LTS 24.8<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Before SR5<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">24.8.13981.17 (SR5)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>M-Files has <a href=\"https:\/\/product.m-files.com\/security-advisories\/cve-2025-13008\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> patched versions addressing this vulnerability. The company received responsible vulnerability disclosure, and no public exploits currently exist.<\/p>\n<p>However, the low probability of exploitation designation should not diminish the urgency of patching.<\/p>\n<p>Given the high-impact nature of successful attacks, <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-atlas-exposes-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">unauthorized<\/a> document access, and potential lateral movement within enterprise systems.<\/p>\n<p>Organizations should prioritize testing and deploying patches across all affected M-Files Server instances.<\/p>\n<p>Simultaneously, security teams should monitor access logs for suspicious user activity that indicates <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">token theft<\/a> or unauthorized account use.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/m-files-vulnerability\/\">M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/m-files-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users An information disclosure vulnerability in M-Files Server enables authenticated attackers to capture and reuse session tokens from active users. Potentially gaining unauthorized access to sensitive document management systems. The flaw, tracked as CVE-2025-13008, affects multiple versions across different release branches and carries a high-severity [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-9509","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9509"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9509"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9509\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}