Mbconnectline

Mymbconnect24

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:34

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.

  • EPSS 0.28%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:35

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.

  • EPSS 0.31%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:35

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.

  • EPSS 0.24%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:35

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.

  • EPSS 0.05%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:35

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.

  • EPSS 0.29%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:35

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public in...

  • EPSS 0.29%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:36

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.

  • EPSS 0.8%
  • Veröffentlicht 16.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:36

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

  • EPSS 0.4%
  • Veröffentlicht 02.10.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:15:00

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.

  • EPSS 0.13%
  • Veröffentlicht 30.09.2020 18:15:25
  • Zuletzt bearbeitet 21.11.2024 05:15:00

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.