MB Connect Line SQL Injection Vulnerability in Mbconnect24 and Mymbconnect24

Vulnerability

A remote SQL injection vulnerability has been identified in the 'setinfo' endpoint of MB Connect Line's mbCONNECT24 and mymbCONNECT24 applications, affecting versions 2.19.4 and prior. This vulnerability allows unauthenticated attackers to manipulate SQL UPDATE commands, leading to unauthorized write access to the user table. The flaw arises from inadequate sanitization of special characters in SQL commands, creating opportunities for injection attacks.

Impact

Exploitation of this vulnerability allows for arbitrary write access to the user table, potentially leading to unauthorized modifications of user data.

Remediation

Users are advised to update their mbCONNECT24 or mymbCONNECT24 instances to version 2.19.5.

Added: Apr 2, 2026, 10:54 AM
Updated: Apr 2, 2026, 10:54 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.7
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.