Unrated severityNVD Advisory· Published Jun 6, 2023· Updated Jan 7, 2025
Helmholz and MB Connect Line: Account takeover via password reset in multiple products
CVE-2023-1779
Description
Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another accounts contact information.
Affected products
4- Range: 1.0.0
- Range: 1.0.0
- Helmholz/myREX24v5Range: 0
- Helmholz/myREX24.virtualv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.