An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.
| Vendor | Product | Versions |
|---|---|---|
| mb connect line | mbconnect24 | 0.0.0, 0.0.0 |
Updated affected versions to include 2.19.4, changed severity to HIGH, and noted that no exploit exists.
Initial creation