VYPR

Misecuremessages

Sign in to watch

by Amtelco

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2014-23470.040.08May 6, 2014Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
CVE-2014-03570.000.02Apr 15, 2014Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.