ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-33282
+2 in the same advisory: …33284 …33283
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials.

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • marvalglobal msm
CVE-2022-31885
+4 in the same advisory: …31887 …31883 …31886 …31884
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

NVD description · AI analysis pending
9.8
group max
33% PoC ×2
  • marvalglobal marval msm