First published: Tue Apr 14 2020(Updated: )
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discover database and table names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mbconnectline Mbconnect24 | <=2.5.0 | |
Mbconnectline Mymbconnect24 | <=2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-10381.
The affected software is MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 versions up to and including 2.5.0.
The severity of CVE-2020-10381 is medium, with a CVSS score of 5.3.
The CWE for this vulnerability is CWE-89, which relates to SQL injection vulnerabilities.
Yes, please refer to the following link for security advice and potential fixes: https://mbconnectline.com/security-advice/