Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-37774

Опубликовано: 23 нояб. 2022
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:maarch:maarch_rm:*:*:*:*:*:*:*:*
Версия от 2.8 (включая) до 2.8.6 (исключая)
cpe:2.3:a:maarch:maarch_rm:2.9:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 5.3
github
около 3 лет назад

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287
CWE-287