MB connect line mbCONNECT24
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*
- <= 2.19.4
- 2.19.4
A remote SQL injection vulnerability has been identified in the 'setinfo' endpoint of MB Connect Line's mbCONNECT24 and mymbCONNECT24 applications, affecting versions 2.19.4 and prior. This vulnerability allows unauthenticated attackers to manipulate SQL UPDATE commands, leading to unauthorized write access to the user table. The flaw arises from inadequate sanitization of special characters in SQL commands, creating opportunities for injection attacks.
Exploitation of this vulnerability allows for arbitrary write access to the user table, potentially leading to unauthorized modifications of user data.
Users are advised to update their mbCONNECT24 or mymbCONNECT24 instances to version 2.19.5.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.