Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://marvalglobal.com/ | product vendor advisory |
https://drive.google.com/drive/folders/1Qa-6-LUzEnduSGfWLUjVLCyKr5wuEu5k?usp=sharing | third party advisory exploit |
https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/os-command-injection | third party advisory exploit |