#VU47171 Command Injection in mymbCONNECT24 and mbCONNECT24
Published: September 30, 2020
mymbCONNECT24
mbCONNECT24
MB connect line
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation. A remote unauthenticated attacker can use an outdated and unused third-party software bundled with the software and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.