CVE-2020-24570: CSRF
Published Sep 29, 2020
·Updated
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the commb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.
Affected Software
2 affected components
Mbconnectline Mbconnect24<=2.6.1
Mbconnectline Mymbconnect24<=2.6.1
Event History
Sep 29, 2020
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-24570.
2
What is the severity level of CVE-2020-24570?
The severity level of CVE-2020-24570 is medium.
3
What is the affected software of CVE-2020-24570?
The affected software of CVE-2020-24570 is MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through version 2.6.1.
4
What is the CWE ID associated with CVE-2020-24570?
The CWE ID associated with CVE-2020-24570 is CWE-352 and CWE-918.
5
How can an attacker exploit the vulnerability in CVE-2020-24570?
An attacker can exploit the vulnerability in CVE-2020-24570 by using a crafted link to steal session information from logged-in users.