PT-2022-20971 · Marval · Marval Msm

Published

2022-06-28

·

Updated

2022-07-14

·

CVE-2022-31883

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Marval MSM version 14.19.0.12476
Description The issue is related to an Insecure Direct Object Reference (IDOR) vulnerability. This allows a low-privilege user to access other users' API keys, including those of administrators.
Recommendations For Marval MSM version 14.19.0.12476, consider restricting access to API keys to prevent unauthorized viewing, especially for low-privilege users, until a patch is available. As a temporary workaround, limit the visibility of API keys to only those who need them, and avoid using the vulnerable API endpoint that allows low-privilege users to see other users' API keys.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31883

Affected Products

Marval Msm