Vulnerabilities > Mbconnectline > Mbconnect24 > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-02 CVE-2020-12530 Cross-site Scripting vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2.
network
low complexity
mbconnectline CWE-79
6.1
2021-03-02 CVE-2020-12529 Server-Side Request Forgery (SSRF) vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
network
low complexity
mbconnectline CWE-918
5.3
2021-02-16 CVE-2020-35570 Forced Browsing vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2.
network
low complexity
mbconnectline helmholz CWE-425
5.3
2021-02-16 CVE-2020-35569 Cross-site Scripting vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-79
6.1
2021-02-16 CVE-2020-35568 Information Exposure vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
network
low complexity
mbconnectline helmholz CWE-200
4.3
2021-02-16 CVE-2020-35566 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
network
low complexity
mbconnectline helmholz CWE-706
5.3
2021-02-16 CVE-2020-35563 Cross-site Scripting vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-79
5.4
2021-02-16 CVE-2020-35561 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
network
low complexity
mbconnectline helmholz CWE-918
5.3
2021-02-16 CVE-2020-35560 Open Redirect vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-601
6.1
2021-02-16 CVE-2020-35559 Resource Exhaustion vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-400
4.3