Senaste nytt från Cyberskydd

CVE-2023-33284 - Marval MSM has a Remote Code Execution vulnerability

Marval MSM < v15.2 has a Remote Code Execution vulnerability. An authenticated remote attacker is able to execute code in context of the web server.

CVE-2023-33283 - Marval MSM uses static encryption key for storing secrets

Marval MSM uses a static encryption key for storing secrets in the database. An attacker that gains access to encrypted secrets can decrypt them using keys from another instance.

CVE-2023-33282 - Marval MSM uses unsafe default credentials

Marval MSM < v15.1 has a System account with default credentials. A remote attacker is able to login and create a valid session which makes it possible to make backend calls to certain endpoints in the application.