Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Mymbconnect24
(Mbconnectline)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 33 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-09-30 | CVE-2020-24569 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information. | Mbconnect24, Mymbconnect24 | 4.3 | ||
2020-09-30 | CVE-2020-24570 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link. | Mbconnect24, Mymbconnect24 | 6.5 | ||
2020-10-02 | CVE-2020-24568 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information. | Mbconnect24, Mymbconnect24 | 6.5 | ||
2021-02-16 | CVE-2020-35557 | An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation. | Myrex24, Myrex24\.virtual, Mbconnect24, Mymbconnect24 | 6.5 | ||
2021-02-16 | CVE-2020-35558 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials. | Myrex24, Myrex24\.virtual, Mbconnect24, Mymbconnect24 | 7.5 | ||
2021-02-16 | CVE-2020-35559 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users. | Mbconnect24, Mymbconnect24 | 4.3 | ||
2021-02-16 | CVE-2020-35560 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php. | Mbconnect24, Mymbconnect24 | 6.1 | ||
2021-02-16 | CVE-2020-35561 | An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports. | Myrex24, Myrex24\.virtual, Mbconnect24, Mymbconnect24 | 5.3 | ||
2021-02-16 | CVE-2020-35563 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page. | Mbconnect24, Mymbconnect24 | 5.4 | ||
2021-02-16 | CVE-2020-35564 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code. | Mbconnect24, Mymbconnect24 | 7.5 |