In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
| Software | From | Fixed in |
|---|---|---|
| mbconnectline / mbconnect24 | - | 2.9.0.x |
| mbconnectline / mymbconnect24 | - | 2.9.0.x |