PT-2021-10874 · Dconnect · Connect

Published

2021-07-21

·

Updated

2021-07-30

·

CVE-2020-23282

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mConnect application version v02.001.00
Description The issue allows an attacker to use a non-existing user with a generic password to connect to the application and gain access to unauthorized information through SQL injection in the Logon Page.
Recommendations For version v02.001.00, consider restricting access to the Logon Page until a fix is available, and avoid using generic passwords to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23282

Affected Products

Connect