Vulnerability Description
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marvalglobal | Marval Msm | 14.19.0.12476 |
Related Weaknesses (CWE)
References
- https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/idor-leads-to-unauthorizeThird Party Advisory
- https://drive.google.com/drive/folders/17Q8ItseCzj5W7wlD6ZFqL0y1N5Emxz4_?usp=shaBroken LinkThird Party Advisory
- https://marvalglobal.com/ProductVendor Advisory
- https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/idor-leads-to-unauthorizeThird Party Advisory
- https://drive.google.com/drive/folders/17Q8ItseCzj5W7wlD6ZFqL0y1N5Emxz4_?usp=shaBroken LinkThird Party Advisory
- https://marvalglobal.com/ProductVendor Advisory
FAQ
What is CVE-2022-31883?
CVE-2022-31883 is a vulnerability with a CVSS score of 8.8 (HIGH). Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
How severe is CVE-2022-31883?
CVE-2022-31883 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31883?
Check the references section above for vendor advisories and patch information. Affected products include: Marvalglobal Marval Msm.