Severity

7.7

Vulnerability Type

Improper Privilege Management (CWE-269)

Summary

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.

Impact

Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.