An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root account.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://mbconnectline.com/security-advice/ | vendor advisory |
https://cert.vde.com/de-de/advisories/vde-2021-003 | third party advisory |