An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
References
Link | Resource |
---|---|
https://cert.vde.com/de-de/advisories/vde-2021-003 | Third Party Advisory |
https://mbconnectline.com/security-advice/ | Vendor Advisory |
https://cert.vde.com/de-de/advisories/vde-2021-003 | Third Party Advisory |
https://mbconnectline.com/security-advice/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert.vde.com/de-de/advisories/vde-2021-003 - Third Party Advisory | |
References | () https://mbconnectline.com/security-advice/ - Vendor Advisory |
Information
Published : 2021-02-16 16:15
Updated : 2024-11-21 05:27
NVD link : CVE-2020-35563
Mitre link : CVE-2020-35563
CVE.ORG link : CVE-2020-35563
JSON object : View
Products Affected
mbconnectline
- mbconnect24
- mymbconnect24
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')