An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an SSRF in thein the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.
References
| Link | Resource |
|---|---|
| https://cert.vde.com/de-de/advisories/vde-2021-003 | Third Party Advisory |
| https://mbconnectline.com/security-advice/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-02-16 16:15
Updated : 2021-02-19 19:57
NVD link : CVE-2020-35558
Mitre link : CVE-2020-35558
JSON object : View
Products Affected
mbconnectline
- mbconnect24
- mymbconnect24
CWE
CWE-918
Server-Side Request Forgery (SSRF)
