CVE-2022-37772
- EPSS 0.47%
- Veröffentlicht 23.11.2022 02:15:09
- Zuletzt bearbeitet 25.04.2025 21:15:33
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compro...
CVE-2022-37773
- EPSS 0.64%
- Veröffentlicht 23.11.2022 00:15:10
- Zuletzt bearbeitet 29.04.2025 16:15:24
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
CVE-2022-37774
- EPSS 0.21%
- Veröffentlicht 23.11.2022 00:15:10
- Zuletzt bearbeitet 29.04.2025 05:15:41
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the fi...
CVE-2019-15854
- EPSS 0.8%
- Veröffentlicht 17.01.2020 17:16:35
- Zuletzt bearbeitet 21.11.2024 04:29:36
An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration privileges via a crafted PUT request to an unauthorized resource.
CVE-2019-15855
- EPSS 1.34%
- Veröffentlicht 17.01.2020 17:16:35
- Zuletzt bearbeitet 21.11.2024 04:29:36
An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the default installation procedure was followed. This results in a permane...