PT-2021-11794 · Unknown · Mbconnect24

Published

2021-02-16

·

Updated

2021-02-19

·

CVE-2020-35563

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: mbCONNECT24 versions through 2.6.2 mymbCONNECT24 versions through 2.6.2
Description: An issue was discovered allowing an attacker to inject crafted malicious code into the page due to an incomplete XSS filter.
Recommendations: For mbCONNECT24 versions through 2.6.2, update to a version that includes a complete XSS filter to prevent malicious code injection. For mymbCONNECT24 versions through 2.6.2, update to a version that includes a complete XSS filter to prevent malicious code injection. As a temporary workaround, consider restricting user input to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35563

Affected Products

Mbconnect24