First published: Tue Mar 02 2021(Updated: )
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mbconnectline Mbconnect24 | <=2.6.2 | |
Mbconnectline Mymbconnect24 | <=2.6.2 |
Update to v2.7.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-12528.
The severity of CVE-2020-12528 is high.
The affected software of CVE-2020-12528 is MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2.
CVE-2020-12528 is an issue in MB connect line mymbCONNECT24 and mbCONNECT24 software that allows a logged in user to kill web2go sessions in the account he should not have access to.
There is no information available about a fix for CVE-2020-12528 at the moment.