Share: Email | Twitter

ID

VDE-2020-035

Published

2020-09-18 14:30 (CEST)

Last update

2020-09-18 14:30 (CEST)

Vendor(s)

MB connect line GmbH

Product(s)

Article No┬░ Product Name Affected Version(s)
mbCONNECT24 <= 2.6.1
mymbCONNECT24 <= 2.6.1

Summary

Multiples issues exist in mymbCONNECT24 and mbCONNECT24

Vulnerabilities



Last Update
Nov. 17, 2022, 10:47 a.m.
Weakness
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") (CWE-89)
Summary
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.
Last Update
Nov. 17, 2022, 10:47 a.m.
Weakness
Cross-Site Request Forgery (CWE-352)
Summary

An issue was discovered in the mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.1. There is a SSRF and CSRF issue, in the com_mb24proxy module, allowing attackers to steal session information from logged in users with a specifically crafted link.

Last Update
Nov. 17, 2022, 10:47 a.m.
Weakness
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") (CWE-89)
Summary
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.

Impact

Please consult the above CVEs for details.

Solution

Update mymbCONNECT24 and mbCONNECT24 to version > v2.6.1

Reported by