CVE-2020-24569: SQL Injection
Published Sep 29, 2020
·Updated
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.
Affected Software
2 affected components
Mbconnectline Mbconnect24<=2.6.1
Mbconnectline Mymbconnect24<=2.6.1
Event History
Sep 29, 2020
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-24569.
2
What is the affected software?
The affected software is MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 version up to and including 2.6.1.
3
What is the severity of CVE-2020-24569?
The severity of CVE-2020-24569 is medium, with a severity value of 4.3.
4
How does CVE-2020-24569 impact the system?
CVE-2020-24569 allows logged in attackers to perform blind SQL injection and discover arbitrary information.
5
How can I fix CVE-2020-24569?
To fix CVE-2020-24569, it is recommended to update the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software to version 2.6.2 or higher.