Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0985


An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.


Published

2023-06-06T11:15:09.093

Last Modified

2024-11-21T07:38:14.077

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mbconnectline mbconnect24 ≤ 2.13.3 Yes
Application mbconnectline mymbconnect24 ≤ 2.13.3 Yes

References