Skip to main content

Vendor/product archive

marvalglobal / marval_msm CVEs

Beta · best-effort

5 CVEs tagged to marvalglobal / marval_msm2 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-31887

Published Jun 28, 2022

Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can als…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31884

Published Jun 28, 2022

Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31886

Published Jun 28, 2022

Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31885

Published Jun 28, 2022

Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31883

Published Jun 28, 2022

Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1