ZeroHour

CVE-2020-10381

CVSS 3.1
5.3 medium
EPSS
1%p64
Published
()
Modified
Description

An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discover database and table names.

Vendors
mbconnectline
Products
mbconnect24, mymbconnect24
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.