Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mbconnectline mbconnect24 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2020-35564
An issue exists in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 up to and including 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
Mbconnectline Mbconnect24
Mbconnectline Mymbconnect24
5
CVSSv2
CVE-2020-35565
An issue exists in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 up to and including 2.6.2. The login pages bruteforce detection is disabled by default.
Mbconnectline Mbconnect24
Mbconnectline Mymbconnect24
4.6
CVSSv2
CVE-2020-35567
An issue exists in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 up to and including 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
Mbconnectline Mbconnect24
Mbconnectline Mymbconnect24
4.3
CVSSv2
CVE-2020-35569
An issue exists in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 up to and including 2.6.2. There is a self XSS issue with a crafted cookie in the login page.
Mbconnectline Mbconnect24
Mbconnectline Mymbconnect24
5
CVSSv2
CVE-2021-34575
In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.
Mbconnectline Mymbconnect24
Mbconnectline Mbconnect24
4
CVSSv2
CVE-2020-24568
An issue exists in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 up to and including 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in malicious users to discover arbitrary information.
Mbconnectline Mymbconnect24
Mbconnectline Mbconnect24
4.3
CVSSv2
CVE-2020-24570
An issue exists in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 up to and including 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing malicious users to steal session information from logged-in users with a crafted link.
Mbconnectline Mymbconnect24
Mbconnectline Mbconnect24
5
CVSSv2
CVE-2020-10381
An issue exists in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions up to and including 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing malicious users to discover database and table names.
Mbconnectline Mymbconnect24
Mbconnectline Mbconnect24
6.5
CVSSv2
CVE-2020-10382
An issue exists in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions up to and including 2.5.0. There is an authenticated remote code execution in the backup-scheduler.
Mbconnectline Mymbconnect24
Mbconnectline Mbconnect24
7.5
CVSSv2
CVE-2020-10383
An issue exists in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions up to and including 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module.
Mbconnectline Mymbconnect24
Mbconnectline Mbconnect24
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »