← Back

Msm

msm

Vendor: Marvalglobal • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Marvalglobal
1Msm
Jan 7, 2025
Jun 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.
1Marvalglobal
1Msm
Jan 7, 2025
Jun 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.
1Marvalglobal
1Msm
Jan 7, 2025
Jun 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the app...Show more
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.Show less