Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Name | Vendor | Start Version | End Version |
---|---|---|---|
M-files_client | M-files | * | 22.5.11356.0 (excluding) |