CVE-2021-34580

Publication date

2021-10-27 10:25:09

Family

CERTVDE

State

PUBLISHED

Description

In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.