An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
References
Link | Resource |
---|---|
https://cert.vde.com/de-de/advisories/vde-2021-003 | Third Party Advisory |
https://mbconnectline.com/security-advice/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Feb 2021, 20:19
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.4 |
References | (MISC) https://cert.vde.com/de-de/advisories/vde-2021-003 - Third Party Advisory | |
References | (MISC) https://mbconnectline.com/security-advice/ - Vendor Advisory | |
CWE | CWE-79 | |
CPE | cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:* cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:* |
16 Feb 2021, 16:41
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-02-16 16:15
Updated : 2023-12-10 13:41
NVD link : CVE-2020-35563
Mitre link : CVE-2020-35563
CVE.ORG link : CVE-2020-35563
JSON object : View
Products Affected
mbconnectline
- mymbconnect24
- mbconnect24
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')