Lucene search

K
cvelistMitreCVELIST:CVE-2022-37774
HistoryNov 22, 2022 - 12:00 a.m.

CVE-2022-37774

2022-11-2200:00:00
mitre
www.cve.org
cve-2022-37774
broken access control
maarch rm 2.8.3
unauthorized access

0.001 Low

EPSS

Percentile

33.5%

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document’s URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

0.001 Low

EPSS

Percentile

33.5%

Related for CVELIST:CVE-2022-37774