Skip to main content

Vendor archive

maarch CVEs

Beta · best-effort

8 CVEs tagged to vendor maarch1 Critical, 3 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-37772

Published Nov 23, 2022

Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37774

Published Nov 23, 2022

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the ap…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37773

Published Nov 23, 2022

An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15855

Published Jan 17, 2020

An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15854

Published Jan 17, 2020

An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration pr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1587

Published Feb 19, 2015

Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8995

Published Nov 20, 2014

SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5492

Published Oct 25, 2006

Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (document contents) via unspecified attack vect…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1