PT-2021-10874 · Dconnect · Connect
Published
2021-07-21
·
Updated
2021-07-30
·
CVE-2020-23282
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
mConnect application version v02.001.00
Description
The issue allows an attacker to use a non-existing user with a generic password to connect to the application and gain access to unauthorized information through SQL injection in the Logon Page.
Recommendations
For version v02.001.00, consider restricting access to the Logon Page until a fix is available, and avoid using generic passwords to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connect