First published: Tue Feb 16 2021(Updated: )
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mbconnectline Mbconnect24 | <=2.6.2 | |
Mbconnectline Mymbconnect24 | <=2.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35560 is a vulnerability in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through version 2.6.2 that allows for an unauthenticated open redirect in the redirect.php file.
CVE-2020-35560 has a severity rating of 6.1 (medium).
As a user, you cannot exploit CVE-2020-35560 directly. It is a vulnerability that can be exploited by attackers to perform an unauthenticated open redirect.
To fix CVE-2020-35560, update MB CONNECT LINE mymbCONNECT24 or mbCONNECT24 to version 2.6.3 or later.
You can find more information about CVE-2020-35560 at the following references: [VDE Advisory](https://cert.vde.com/de-de/advisories/vde-2021-003) and [MB CONNECT LINE Security Advice](https://mbconnectline.com/security-advice/).