CVE-2020-35570

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

Information

Published : 2021-02-16 16:15

Updated : 2021-02-19 20:06


NVD link : CVE-2020-35570

Mitre link : CVE-2020-35570


JSON object : View

Products Affected

mbconnectline

  • mbconnect24
  • mymbconnect24
CWE
CWE-425

Direct Request ('Forced Browsing')