An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a get parameter.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.vde.com/de-de/advisories/vde-2021-003 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2021-03-02T21:15:25.258645Z
Updated: 2024-09-16T19:55:41.845Z
Reserved: 2020-04-30T00:00:00
Link: CVE-2020-12530
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-02T22:15:12.667
Modified: 2024-11-21T04:59:52.803
Link: CVE-2020-12530
Redhat
No data.