Products: 4
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-37772

    Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.

    Last Modified: Apr 25, 2025
    Published: Nov 23, 2022

    CVE-2022-37773

    An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.

    Last Modified: Apr 29, 2025
    Published: Nov 22, 2022

    CVE-2022-37774

    There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

    Last Modified: Apr 29, 2025
    Published: Nov 22, 2022

    CVE-2019-15854

    An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration privileges via a crafted PUT request to an unauthorized resource.

    Last Modified: Nov 21, 2024
    Published: Jan 17, 2020

    CVE-2019-15855

    An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the default installation procedure was followed. This results in a permanent Denial of Service.

    Last Modified: Nov 21, 2024
    Published: Jan 17, 2020
    Items Per Page