An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://mbconnectline.com/security-advice/ | vendor advisory |
https://cert.vde.com/de-de/advisories/vde-2021-003 | third party advisory |