CVE-2020-23282

SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mv:mconnect:02.001.00:*:*:*:*:*:*:*
cpe:2.3:a:mv:mconnect:2013.1.6.8:*:*:*:*:*:*:*

Information

Published : 2021-07-21 08:15

Updated : 2021-07-30 06:58


NVD link : CVE-2020-23282

Mitre link : CVE-2020-23282


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

mv

  • mconnect