Vulnerability Description
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marvalglobal | Marval Msm | 14.19.0.12476 |
Related Weaknesses (CWE)
References
- https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/2fa-bypass-via-x-csrfExploitThird Party Advisory
- https://drive.google.com/drive/folders/1Zy5Oa-maLo0ACfLz90uvxqxwG18DwAZYExploitThird Party Advisory
- https://marvalglobal.com/ProductVendor Advisory
- https://www.servicedeskinstitute.com/casestudies/who-is-marval-software/Third Party Advisory
- https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/2fa-bypass-via-x-csrfExploitThird Party Advisory
- https://drive.google.com/drive/folders/1Zy5Oa-maLo0ACfLz90uvxqxwG18DwAZYExploitThird Party Advisory
- https://marvalglobal.com/ProductVendor Advisory
- https://www.servicedeskinstitute.com/casestudies/who-is-marval-software/Third Party Advisory
FAQ
What is CVE-2022-31886?
CVE-2022-31886 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
How severe is CVE-2022-31886?
CVE-2022-31886 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31886?
Check the references section above for vendor advisories and patch information. Affected products include: Marvalglobal Marval Msm.