Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4j8-5xv4-xcxh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

EPSS

Процентиль: 49%
0.0026
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-669

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

EPSS

Процентиль: 49%
0.0026
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-669