Vulnerabilities (CVE)

Filtered by vendor Marvalglobal Subscribe
Filtered by product Marval Msm
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31884 1 Marvalglobal 1 Marval Msm 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
CVE-2022-31886 1 Marvalglobal 1 Marval Msm 2022-07-08 4.3 MEDIUM 6.5 MEDIUM
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.