Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-86392
HistoryNov 25, 2022 - 12:00 a.m.

Maarch RM Information Disclosure Vulnerability

2022-11-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
maarch rm
information disclosure
vulnerability
electronic archiving
security incident
access control

0.001 Low

EPSS

Percentile

33.5%

Maarch RM is an electronic archiving system from Maarch Inc. Streamline your authentication process, science and technical control in an efficient and optimized manner.An information disclosure vulnerability exists in Maarch RM 2.8 and later, versions prior to 2.8.6, and 2.9. The vulnerability stems from the fact that when accessing certain specific documents (pdf, email) from an archive, the application suggests a preview that generates a URL containing an md5 hash of the accessed file with no access rights verification. An attacker could exploit the vulnerability to obtain sensitive information.

0.001 Low

EPSS

Percentile

33.5%

Related for CNVD-2022-86392