Vulnerabilities > Marvalglobal
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-07 | CVE-2023-33282 | Incorrect Default Permissions vulnerability in Marvalglobal MSM 15.0 Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. | 9.8 |
2023-06-07 | CVE-2023-33283 | Inadequate Encryption Strength vulnerability in Marvalglobal MSM Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. | 5.5 |
2023-06-07 | CVE-2023-33284 | Deserialization of Untrusted Data vulnerability in Marvalglobal MSM 15.0 Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. | 8.8 |
2022-06-28 | CVE-2022-31884 | Unspecified vulnerability in Marvalglobal Marval MSM 14.19.0.12476 Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys. | 6.5 |
2022-06-28 | CVE-2022-31887 | Insufficiently Protected Credentials vulnerability in Marvalglobal Marval MSM 14.19.0.12476 Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password. | 9.8 |
2022-06-28 | CVE-2022-31883 | Authorization Bypass Through User-Controlled Key vulnerability in Marvalglobal Marval MSM 14.19.0.12476 Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. | 8.8 |
2022-06-28 | CVE-2022-31885 | OS Command Injection vulnerability in Marvalglobal Marval MSM 14.19.0.12476 Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | 9.8 |
2022-06-28 | CVE-2022-31886 | Cross-Site Request Forgery (CSRF) vulnerability in Marvalglobal Marval MSM 14.19.0.12476 Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). | 6.5 |