Marvalglobal
Marvalglobal Marval MSM: vulnerabilidades y CVE
Marvalglobal Marval MSM tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-31887 | Crítica (9.8) | 1.6% | — | 28 jun 2022 | Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation… |
| CVE-2022-31884 | Media (6.5) | 1.2% | — | 28 jun 2022 | Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys. |
| CVE-2022-31886 | Media (6.5) | 2.2% | — | 28 jun 2022 | Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form. |
| CVE-2022-31885 | Crítica (9.8) | 33% | — | 28 jun 2022 | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. |
| CVE-2022-31883 | Alta (8.8) | 0.97% | — | 28 jun 2022 | Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys. |