Security Advisory

CVE-2021-34580

7.5
HIGH

Vulnerability Description

In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
Published Date October 27, 2021
Official Source NIST NVD Advisory