CVE-2020-12530
Summary
| CVE | CVE-2020-12530 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-02 22:15:00 UTC |
| Updated | 2021-03-09 16:03:00 UTC |
| Description | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a get parameter. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mbconnectline | Mbconnect24 | All | All | All | All |
| Application | Mbconnectline | Mymbconnect24 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MB connect line: Multiple vulnerabilites in mymbCONNECT24 and mbCONNECT24 <= 2.6.2 — German (Germany) | CONFIRM | cert.vde.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: OTORIO reported the vulnerabilities to MB connect line. CERT@VDE coordinated.
There are currently no legacy QID mappings associated with this CVE.