CVE-2023-1779

Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another accounts contact information.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-06 11:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1779

Mitre link : CVE-2023-1779

CVE.ORG link : CVE-2023-1779


JSON object : View

Products Affected

mbconnectline

  • mymbconnect24
  • mbconnect24
CWE
CWE-863

Incorrect Authorization

NVD-CWE-noinfo