MB connect line mbCONNECT24
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*
- <= 2.20.0
- 2.20.0
A SQL injection vulnerability has been identified in the DevSerialReset function of MB Connect Line's mbCONNECT24 and mymbCONNECT24 products, all versions through 2.20.0. This vulnerability allows high-privileged remote attackers to exploit improper handling of special elements in a SQL UPDATE command. As a result, attackers can read the entire database and modify values in a non-critical table, leading to a complete loss of confidentiality and some loss of integrity.
Exploitation of this vulnerability allows for unauthorized SQL injection, enabling attackers to read the entire database and modify values in a non-critical table.
Users are advised to update to version 2.20.1 of mbCONNECT24 or mymbCONNECT24.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.