An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root account.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mbconnect24 | Mbconnectline | * | 2.6.1 (including) |
Mymbconnect24 | Mbconnectline | * | 2.6.1 (including) |