Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfjj-6wq7-4f8w

Опубликовано: 07 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

EPSS

Процентиль: 26%
0.0009
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

EPSS

Процентиль: 26%
0.0009
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276