An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
References
Link | Resource |
---|---|
https://cert.vde.com/de-de/advisories/vde-2021-003 | Third Party Advisory |
https://mbconnectline.com/security-advice/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-02-16 08:15
Updated : 2021-02-19 12:19
NVD link : CVE-2020-35563
Mitre link : CVE-2020-35563
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
mbconnectline
- mymbconnect24
- mbconnect24