Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another accounts contact information.
2023-06-06T11:15:09.913
2024-11-21T07:39:53.470
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mbconnectline | mbconnect24 | ≤ 2.13.3 | Yes |
Application | mbconnectline | mymbconnect24 | ≤ 2.13.3 | Yes |