Vulnerabilities > Mbconnectline

DATE CVE VULNERABILITY TITLE RISK
2021-02-16 CVE-2020-35563 Cross-site Scripting vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
3.5
2021-02-16 CVE-2020-35561 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
network
low complexity
mbconnectline helmholz CWE-918
5.3
2021-02-16 CVE-2020-35560 Open Redirect vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
5.8
2021-02-16 CVE-2020-35559 Resource Exhaustion vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-400
4.0
2021-02-16 CVE-2020-35558 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2.
network
low complexity
mbconnectline helmholz CWE-918
7.5
2021-02-16 CVE-2020-35557 Improper Privilege Management vulnerability in multiple products
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.
network
low complexity
mbconnectline helmholz CWE-269
6.5
2020-10-02 CVE-2020-24568 SQL Injection vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1.
network
low complexity
mbconnectline CWE-89
4.0
2020-09-30 CVE-2020-24570 Cross-Site Request Forgery (CSRF) vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1.
4.3
2020-09-30 CVE-2020-24569 SQL Injection vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1.
network
low complexity
mbconnectline CWE-89
4.0
2020-04-14 CVE-2020-10384 Improper Privilege Management vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1.
local
low complexity
mbconnectline CWE-269
7.2