An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mbconnectline Mbconnect24
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
|
— |
<= 2.19.4
|
|
Mbconnectline Mymbconnect24
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*
|
— |
<= 2.19.4
|