CVE-2020-35563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/02/2021
Last modified:
19/02/2021

Description

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:* 2.6.2 (including)
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:* 2.6.2 (including)