CVE-2019-15855: Maarch Rm

Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the default installation procedure was followed. This results in a permanent Denial of Service.

Affected products

  • Maarch Maarch Rm: before 2.5 (fixed in 2.5)

Published 2020-01-17. Last modified 2026-06-17.